Friday, March 26, 2010

Usability vs Security vs Operability

From a security perspective, the weakest links in the chain are usually the human beings. The end-users' security posture can be dramatically increased by providing simple but continuous security awareness training. The service providers (i.e., banks, government institutions, online-shopping sites) can support this important cause by funding the centralized or distributed security awareness and training initiatives. I think that within the last 10 years (based on my personal observation), there is an increased level of awareness among the end-user community. For the attacks targeting end-users, the attacker community's target is to gather all the "low hanging fruits".


I also want to point out that the technology plays an important role in enabling secure communication between the end-users and the service providers. The password-based authentication is still the main type of authentication used in the real world. Although we know that the security research community came up with 2-factor, 3-factor, (even 4th-factor authentication has been proposed recently http://www.rsa.com/rsalabs/staff/bios/ajuels/publications/fourth-factor/ccs084-juels.pdf), but the reality is that only few government and enterprise organizations adopt the usage of 2 factor authentication for online-access. Majority of the service providers continue using the password based authentication. We need to think about why there is such a low adoption rate for the advanced authentication techniques. I think that the answer lies within the delicate balance between these three properties: usability, security, and operability. Of course, the businesses make their decisions mainly based on how they decide to handle the risk and the return on security investment.

For example, the biometric authentication gained momentum around 2001/2002 but there is certainly some hesitation towards the biometric authentication from the public and the privacy professionals. PKI based digital certificate authentication, for example, can provide non-invasive 2 factor authentication but maintaining the required infrastructure and managing the keys are quite complicated. Implementations of theoretical security ideas sometimes are taking way too long time to produce mature products. Also, I believe that there are still so many companies out there struggling with implementing and keeping up with the basic security measures.

No comments: