Secrets and Lies: Digital Security in a Networked World by Bruce Schneier

NEW FROM BN.COM

  • $17.95 Online Price
  • skip to cart

SPEND $25, GET FREE SHIPPING

Pick Me Up

Want to reserve & pick up at your local store?

  • Enter your zip

(Paperback)

Average Customer Rating:

( 8 customer ratings )

  • Pub. Date: January 2004
  • 448pp
  • Sales Rank: 290,140
    Other Formats 
    Available in eBook$16.49
     
    • Overview
    • Editorial Reviews
    • Customer Reviews
    • Features

    Product Details

    • Pub. Date: January 2004
    • Publisher:Wiley, John & Sons, Incorporated
    • Format: Paperback, 448pp
    • Sales Rank: 290,140

    Synopsis

    Bestselling author Bruce Schneier offers his expert guidance on achieving security on a network Internationally recognized computer security expert Bruce Schneier offers a practical, straightforward guide to achieving security throughout computer networks. Schneier uses his extensive field experience with his own clients to dispel the myths that often mislead IT managers as they try to build secure systems. This practical guide provides readers with a better understanding of why protecting information is harder in the digital world, what they need to know to protect digital information, how to assess business and corporate security needs, and much more.
    * Walks the reader through the real choices they have now for digital security and how to pick and choose the right one to meet their business needs
    * Explains what cryptography can and can't do in achieving digital security

    Electronic Review of Computer Books - Danny Yee

    Bruce Schneier begins Secrets and Lies by saying "I have written this book partly to correct a mistake" -- that being the utopian vision of cryptography in his earlier Applied Cryptography. Of the wonders he predicted in that work, he now writes:

    "Cryptography can't do any of that.
    "... Cryptography is a branch of mathematics. And like all mathematics, it involves numbers, equations, and logic. Security, palpable security that you or I might find useful in our lives, involves people: things people know, relationships between people, people and how they relate to machines. Digital security involves computers: complex, unstable, buggy computers."

    Secrets and Lies, then, is a non-technical introduction to the full, messy complexity of digital security. Cryptography is covered, but only as part of the broader picture and without any mathematics at all. The result is broadly accessible, but many of the ideas it explains are misunderstood even by the technically trained, so it is a work that offers something to techs and managers as well as lay readers.

    Part 1 is a 70-page overview of digital security which could (and perhaps should) be read by anyone who uses the Net. Schneier surveys the threats, covering not just the full range of criminal attacks but also publicity attacks and attacks using the legal system. He categorizes the attackers, who can include national intelligence organizations and the press as well as terrorists, insiders, lone criminals, and corporate spies. And he looks as the various kinds of security we need, among them privacy, anonymity, integrity, authenticity, and audit.

    Part 2 looks at a broad range of security technologies (cryptography and its context, software reliability, secure hardware, identification and authentication, and certificates and credentials) and security domains (computer, networked-computer, and network security), with a final chapter on "the human factor." Schneier provides clear, non-technical explanations of everything from the problems with mobile code to the uses of secure hardware to the limitations of digital certificates. In the process he corrects many common misconceptions about security, including some of the rather misleading statements used in product marketing.

    Part 3, on security strategies, covers the management of digital security. Schneier looks at vulnerabilities, attack methodologies, and countermeasures (protection, detection, and response), stressing the importance of threat modelling and risk assessment (including an approach of his own called "attack trees"). He also covers product testing and verification and the future of products. In the final analysis, however, digital security is about risk management: "security is not a product; it's a process."

    More Reviews and Recommendations

    Biography

    Bruce Schneier is the founder and CTO of Counterpane Internet Security, Inc., the recognized leader in network security services. The bestselling author of Beyond Fear: Thinking Sensibly About Security in an Uncertain World and Applied Cryptography, he is an internationally respected security expert.

    Customer Reviews


    More Customer Reviews

    Be the first to write a review!