Shmoocon: Keynote

| | Comments (0) | TrackBacks (0)

Dan Greer was the Keynote speaker at Shmoocon.

For a statistician he made a rather broad brush statement that current security workers have no formal training. Yet now every college has a security course. The non-credentialed he says are the ones with skills while those with credentials are the charlatians.

Was the world really better when the astronomers where the ones hunting down the hackers? Is the best hacker one with no formal training? It certainly is popular to attack anyone who has bothered to get a certification or a degree as if that certifies them as having no skills at all.

I do agree with his statement that as demand for security professionals outstrips supply, the number of charlatian increases. Its very annoying to watch clueless people stampede after the money. At least in the pre-credential days, you knew people were doing it because they loved the challenge.

Greer also talked about a change in focus from prevention to detection and recovery. Ceeding that attacks will succeed but making sure what is important is recoverable. With strong recovery capability in place, you can apply patches at they are released without a formal q/a process.

Another interesting comment from Greer is that according to Symantec's own data a new virus is released every 4 hours. How often do you update your antivirus definitions? It is a doomed model.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: Shmoocon: Keynote.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/67

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on January 13, 2006 11:14 PM.

Shmoocon was the previous entry in this blog.

Shmoocon: Network Policy enforcement is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.23-en