by Joel Aufrecht 12:59 AM, 07 Nov 2003
I've been skimming Bruce Schneier's book, Secrets and Lies, and finding it a bit disappointing. He's such a good, clear, thorough writer in his online column that the book represents a bit of a step down. It's a basic primer in security, especially computer security. It's still written in his smooth, readable style, but I'm confused by the level of detail. It doesn't offer much new to someone like me, a computer person who more or less keeps up on computer security. It does offer a general overview on a lot of topics, but sometimes he seems to surf over the complexity instead of diving into it and explaining it, which makes me suspect that people who don't already understand the details may not get them. I might be wrong - he covers a lot of basic topics better and shorter than I've seen anywhere else - but it kinda seems like sometimes he introduces a topic, decides he doesn't want to dive into the necessary depth, and then glosses over it, all in the name of being thorough.

My other complaint is that he spends plenty of time talking about users and how they're easily fooled, but very little time talking about how security professionals have failed socially. The single biggest failing of institutional security I've seen is that security people (and network people) are often bullying jerks, and hence get ignored as soon as they're out of sight. If security people understood the day-to-day hassles of their proctectees, and were more often seen as allies and educators instead of unhelpful authorities with only negative powers, it seems like a lot of vulnerabilities would close up.

Categories: Reviews Comments (0)
XML

Archive

November 2003
S M T W T F S
           
2  3  7 
10  11  12  13  14  15 
16  17  18  19  20  21  22 
23  24  25  26  27  28  29 
30             
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004
September 2004
August 2004
July 2004
June 2004
May 2004
April 2004
March 2004
February 2004
January 2004
December 2003
November 2003
October 2003
September 2003
August 2003
July 2003
June 2003
May 2003
April 2003
March 2003
February 2003
January 2003
April 2001

Notifications

You may request notification for Joel's Blog.

Syndication Feed

XML

Recent Comments

  1. Victor Koledoye: A Religion ticket
  2. Joel Aufrecht: from a senior roboticist
  3. Jeff Davis: Source?
  4. Kathryn Schild: quick question
  5. Tai Yan Lim: Trip Back Home - Joel
  6. José Rodrigues: Hello
  7. Guan Yang:
  8. Erika Graffunder: Canada
  9. Erika Graffunder: Per capita emissions
  10. Erika Graffunder: Policy - should you keep evaluating or focus on solutions