Don't neglect desktop when it comes to security
Computerworld - Microsoft finally allows some user control of cookies with Internet Explorer. Napster appears on tens of millions of PCs, and security experts wonder if hackers could use it to invade a system. Advocacy groups express alarm at the amount of user profiling on many corporate sites.
Issues for consumers? Of course, but don't shrug them off. Client security has become the most neglected and vulnerable link in the corporate IT infrastructure.
Sometimes the problem is blatant, like unsecured dial-in lines connected directly to a PC. According to George Kurtz, one of the authors of Hacking Exposed (Osborne/McGraw Hill; 1999) and CEO of Foundstone Inc., a security consulting company, it's possible to break into a corporate network through dial-up connections more than 90% of the time. That risk extends to the home, where PCs - especially with always-on, high-speed Internet connections - get probed 10 to 20 times a day.
Since most home PCs aren't configured to detect and repel such advances, the chances are significant that the more criminally minded could take over such machines. Add a VPN connection into a company's network, and the entire business - potentially - is laid open. Software such as Napster or Gnutella actually invite outsiders onto a hard drive to swap MP3 files. Can a user get anything more than music? There have been no reports of a security failure in such applications, but who would have thought a flaw in Microsoft Outlook (now corrected) would allow hackers to have it run software, like a virus, for them? Betting on the invulnerability of code is like using the lottery as a sole form of retirement planning. Think Napster is missing from your clients? Kurtz tells of finding the program on the production server of a major e-commerce company.
And it gets worse. Imagine that someone could look over the shoulders of developers, engineers, marketing people and business planners to track the Web sites they opened. Those performing product or market research on the Web could leave a visible trail. Such information would be a gold mine to competitors. Even cookies could provide much of this information, let alone surreptitiously placed sniffer programs, and we haven't even started talking about breaking into e-mail. Whether the competitor does the actual snooping or simply buys the information from a third party is immaterial.
Security spending and awareness are typically directed toward servers. It's time to remember that the biggest breach happens at the weakest link in the chain: the desktop. Corporations should treat client machines seriouslyby thoroughly examining security and updating end-user policies. Insist that Internet software vendors provide strong privacy control. Sure, adding such abilities means that gathering information on your customers would be harder, and that would make the marketing department unhappy, but is selling an extra widget to John Smith really worth leaving the company's back door unlocked?
ERIK SHERMAN is a writer in Marshfield, Mass., who regularly covers technology and business issues. Contact him at esherman@reporters.net.
Read more about PCs in Computerworld's PCs Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All PCs White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All PCs Webcasts