TS: The days that you could provide security at the network are gone because it’s an endpoint problem.
MS: Well, security is not network- centric any more.
GI: No, it’s application and user.
TS: We have a fortress mentality where we throw anti-virus, intrusion-prevention systems, secured our routers etc.
GI: But the Government is saying, to deliver their services we want you to be online. Agencies are bluffing people, saying your transaction is secure because our end-systems, our databases are secure.
AM: I bang on about citizens reporting an issue to an authority because until we know what happened we can’t do anything.
MS: Ask a technician what is the internet, the answer will be wires and switches but ask anyone else, it is Google, Twitter, Facebook and applications. Society is more interested in the content.
BG: Corporations aren’t taking responsibility. You sign up for a hotmail account these days it’s still not going over SSL by default.
KP: Directors have a duty of care because their obligation is to be aware of the risks. GI: We are conditioning users to give more information online and that’s what attackers want.
AM: I have a “Wildebeest Mentality” theory that if I run in a herd lions pick out a few on the edges. But it doesn’t work now: they can pillage as many passwords, credit cards, bank logins as they can get their hands on. Criminals are highly efficient at stripping data but surprisingly inefficient at using it.
NC: The criminal cares more. Look at the PlayStation Network crack. Sony had unpatched, randomly patched servers, some holding credit card data for 10 years, in plain text in the clear and they just didn’t care. If organisations cares more about data they’re taking and not just pass it off and leave it on random servers we’d be better off.
L-YW: If you drive in China or India you notice there are no regulations, everybody just drives how they want. But they don’t have a high volume of accidents, because they’re self-governing. So this notion of individual accountability, endpoint protection is probably the way to go with the internet.
TS: In government, I worried about lions; in industry, my clients just say stop them from getting in.
JT: Predators only start to turn on each other when they’ve started to run out of food. So there’s plenty more feeding yet to happen before the predators start turning on each other.