MADRID: The first Security Blogger Summit was held at the Circulo de Bellas Artes on Feb. 3. Organized by Panda Security, the event brought together 200 people involved in IT security and featured a roundtable discussion involving eleven opinion leaders from the United States and Spain.
Blogger and IT security guru Bruce Schneier was a strong voice throughout the day. “We have to bear in mind the economic factors behind the technology that we have,” said Schneier. “We could have better technology, but we are not prepared to pay for it. The market rewards the cool and the fast, but not the good.”
The session started with a 15-minute talk from Schneider. He emphasized the major technological advancement that the Internet represents, calling it “one of the most important revolutions after Rock and Roll.” He also drew attention to the need not to externalize responsibility for security by passing it on to governments, but for users and companies to play their parts. “In the case of credit cards, the government did not educate users, it passed the problem to companies and they investigated. The same has to be done (for IT security). The problem cannot be shifted just to users, but also to banks and other companies.”
Other speakers also put forward their opinions with respect to the responsibility for security. Byron Acohido, tech journalist, USA Today said that, “Ninety percent of the problem is not down to the user. If a system with errors is launched on the market, this is not a problem of the user.” On the other hand, Francisco A. Lago, of the National Institute of Communication Technologies (INTECO) believed that, “The main problem is user behavior” and said that awareness campaigns about good practices were the best vehicle for avoiding security risks.
Andy Willingham, author of the blog Andy ITGuy, and Steve Ragan, security editor for Tech Herald, focused on the need for experts to lead this education, but with simple, comprehensible language. “There are blogs and security media, but users do not understand them and as long as they don't, we will continue to see the same errors time and time again,” underlined Ragan.
All speakers agreed that one of the main trends of the last few years has been the increasing professionalism of cyber-criminals.
Cesar Lorenzana, from the Technology Crime Division of the Spanish Civil Guard explained, “It's not that there is more malware, it's that malware is now profitable for criminals. It's a way of earning a living.” And it is quite a good living. Acohido gave the example of the German cyber-crime gang known as Cosmos, who earned $7 million from attacks in just one week!
Lago emphasized the false sense of security among users, “Eighty percent of users believe that their computers are protected, yet three quarters of them are infected.”

