The Security Mindset

Bruce Schneier had an excellent post on his blog this week about the security mindset.  The reason that existing voting machines are not secure is because the basic engineering mindset does not include the sneaky attitude required to design a secure system.  From the post:

The lack of a security mindset explains a lot of bad security out there: voting machines, electronic payment cards, medical devices, ID cards, internet protocols. The designers are so busy making these systems work that they don’t stop to notice how they might fail or be made to fail, and then how those failures might be exploited. Teaching designers a security mindset will go a long way toward making future technological systems more secure.

One Response to “The Security Mindset”

  1. AllAboutVoting Says:

    Ben Adida writes about the same subject in the context of voting machines - from the point of view of users/buyers of systems rather then designers.

Leave a Reply