Bruce Schneier on IT Insecurity

There are no easy solutions to today's security challenges, and companies often approach them in the wrong way, says Bruce Schneier.

  • Edward Cone
  • CIO Insight
  • December 16, 2008

Talking with security expert Bruce Schneier does not always leave a person feeling more secure. That’s because Schneier doesn’t sell easy solutions. Instead, he challenges businesses, governments and individuals to examine their assumptions about risk, to eschew simplistic answers and to accept the fact that no system is—or can be—perfectly secure.

Now the chief security technology officer of BT, Schneier worked at the Department of Defense and Bell Labs before founding Counterpane Internet Security, which was acquired by BT. He has a master’s degree in computer science and a B. A. in physics…

Book Review: Beyond Fear

  • Paul B. Brown
  • CIO Insight
  • September 1, 2003

The most appealing part of Bruce Schneier’s thorough, well-reasoned approach to security strategies—personal, corporate and computer—is what he does not do. He does not propose concrete solutions (“We need more police. We need national ID cards. You need to build better firewalls.”) Instead, he lays out the issues, debates the pros and cons, and leaves it to the reader to pick a solution.

What makes the discussion worthwhile is that Schneier, founder of consulting firm Counterpane Internet Security Inc. and publisher of the security newsletter Crypto-Gram, takes great pains to identify the key issues and examine some proposed solutions, pointing out the costs involved and the likelihood of success. For example, he believes that the idea of using biometric scanners—programmed to search out known criminals and terrorists based on their physical characteristics—probably won’t work because false positives will overwhelm the system…

