Crypto pioneers differ on cloud-computing risks

By Elinor Mills, CNET News.com
Wednesday, April 22, 2009 12:55 PM

SAN FRANCISCO--A group of pioneers in the security field, whose work in encryption is used to protect Internet data and communications every day, spoke about the state of security at a cryptographer's panel at the RSA security conference on Tuesday.

They tackled various questions about cyber security in general, but the topic that dominated was cloud computing.

"Cloud computing is a challenge to security, but one that can be overcome," said Whitfield Diffie, chief security officer at Sun Microsystems. "I believe cloud computing will get to (the point) where no real program...will be done anymore on the computers of the company that's doing it," he said.

"I'm worried about cloud computing," said Adi Shamir, a computer science professor at the Weizmann Institute of Science in Israel. While a virus or other problem on a desktop computer can be a big annoyance, computation centers in hosted computing could spread problems more widely, he said.

Bruce Schneier, chief security technology officer at BT Counterpane, said, "I'm kind of bored with it." Cloud computing is presented as a new paradigm...but fundamentally I don't see a lot of differences" between it and client-server and dumb terminals, he said. "It's still all about trust."

Ronald Rivest, a computer science professor at MIT, predicted that cloud computing "will really be a focal point in our work in security". "I'm optimistic about cloud computing," he said. "I think a lot of us have hard work to do."

Asked about their thoughts on the likelihood of a "Digital Pearl Harbor", the researchers concurred that the threat is hyped.

The talk about risks of a cyberattack on the magnitude of a Pearl Harbor strike is overblown, said Schneier. The real threat "will be boring things" like viruses, identity theft, and buffer overflows. "We're better as an industry if...we look at the more common risks...that cost (people) money."

"We're more likely to suffer a digital 9/11," said Diffie. Pearl Harbor was an attack by a known entity as opposed to an unknown threat from a mysterious source, as cyberattacks tend to be, he said. "I think we could suffer some astounding event," he added, noting that there was an electricity blackout in the 1990s and a severe telephone outage in the 1980s due to a bug.

Shamir said cyberattacks should be put in perspective and compared with other events that can have even more serious consequences. "If the government has extra money to spend they should spend it on regulating the financial markets and not spend it on regulating cybersecurity," he said.

Martin Hellman, professor emeritus at Stanford, said he has been focusing on nuclear weapons security lately and looking at how risky nuclear deterrence is with his NuclearRisk.org site. It's "at least 1,000 times riskier than having a nuclear power plant located near your home," he said.

Technology "has given human beings power that has historically been reserved for the gods; the ability to create new life forms, the ability to destroy civilization, and the potential for creating unbelievable cooperation or unbelievable chaos," he said.

"Our species is like a 16 year old with a new driver's license who somehow gets his hands on a 500-horsepower Ferrari," Hellman said, adding that people need to learn to control our impulses or risk destroying everything.

This article was first published as a blog post on CNET News.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Hands-on programming: Extract plain text from documents with Syncfusion's components

Web Development

Justin James recently tried Syncfusion's Essential DocIO and Essential PDF to help him extract text from documents he downloaded from the Internet. Here's the code he wrote to get the plain text.


Read more »



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web