Secrets and Lies: Digital Security in a Networked World (Hardcover)

Author: Bruce Schneier
Share this Product

List Price:  See Details$29.99
Price: $0.33
Shipping: $3.99

                Low Price: $4.32

Ships from and sold by massbookstore
What's this?
Condition: Used-Very Good
Format: Hardcover
7 Used from $0.33 What's this?
Permalink
Related Videos
Dracula The Undead by Fre...
Dracula The Undead by Freda Warrington 2009 Trailer
Here's the Deal: Don't To...
Here's the Deal: Don't Touch Me by Howie Mandel 2009 Trailer
Powerless by Mathew Cody
Powerless by Mathew Cody 2009 Trailer
Product Summary
Format: Hardcover
ISBN: 9780471253112
Publisher: John Wiley & Sons, Inc.
Publish Date: 10/1/2000
Buy.com Sku: 30642437
Item#: R93DRD
Dimensions (in Inches) 9.25H x 6.75L x 1.25T
Pages: 384
 

From the Publisher:
Bestselling author Bruce Schneier offers his expert guidance on achieving security on a network Internationally recognized computer security expert Bruce Schneier offers a practical, straightforward guide to achieving security throughout computer networks. Schneier uses his extensive field experience with his own clients to dispel the myths that often mislead IT managers as they try to build secure systems. This practical guide provides readers with a better understanding of why protecting information is harder in the digital world, what they need to know to protect digital information, how to assess business and corporate security needs, and much more.

  • Walks the reader through the real choices they have now for digital security and how to pick and choose the right one to meet their business needs
  • Explains what cryptography can and can't do in achieving digital security

    Comments by the Author
    I started writing this book in 1997; it was originally due to the publisher by April 1998. I eventually delivered it in April 2000, two years late. I have never before missed a publication deadline: books,articles, or essays. I pride myself on timeliness: A piece of writing is finished when it's due, not when it's done.

    This book was different. I got two-thirds of the way through the book without giving the reader any hope at all. And it was about then I realized that I didn't have the hope to give. I had reached the limitations of what I thought security technology could do. I had to hide the manuscript away for over a year; it was too depressing to work on.

    I came to security from cryptography, and framed the problem with classical cryptography thinking. Most writings about security come from this perspective, and it can be summed up pretty easily: Security threats are to be avoided using preventive countermeasures.

    For decades we have used this approach to computer security. We draw boxes around the different players and lines between them. We define different attackers -- eavesdroppers, impersonators, thieves -- and their capabilities. We use preventive countermeasures like encryption and access control to avoid different threats. If we can avoid the threats, we've won. If we can't, we've lost.

    Imagine my surprise when I learned that the world doesn't work this way.

    I had my epiphany in April 1999: that security was about risk management, that detection and response were just as important as prevention, and that reducing the "window of exposure" for an enterprise is security's real purpose. I was finally able to finish the book: offer solutions to the problems I posed, a way out of the darkness, hope for the future of computer security.

    "Secrets and Lies" discusses computer security in this context, in words that a business audience will understand. It explains, in my typical style, how different security technologies work and how they fail. It discusses the process of security: what the threats are, who the attackers are, and how to live in their world.

    It'll change the way you think about computer security. I'm very proud of it...

    Table Of Contents:

    THE LANDSCAPE
    Digital Threats
    Attacks
    Adversaries
    Security Needs

    TECHNOLOGIES
    Cryptography
    Cryptography in Context
    Computer Security
    Identification and Authentication
    Networked-Computer Security
    Network Security
    Network Defenses
    Software Reliability
    Secure Hardware
    Certificates and Credentials
    Security Tricks
    The Human Factor.

    STRATEGIES
    Vulnerabilities and the Vulnerability Landscape
    Threat Modeling and Risk Assessment
    Security Policies and Countermeasures
    Attack Trees
    Product Testing and Verification
    The Future of Products
    Security Processes
    Conclusion
    Afterword
    Resources
    Index
     
    Annotation:
    In this straightforward how-to manual, an encryption expert outlines how to protect computer networks from internal and external threats.

     

Praise
Business 2.0
"[This book] is a comprehensive, well-written work on a topic few business leaders can afford to neglect." 10/24/2000

Industry Standard
"[An] engaging and exhaustive new book....[Schneier's] prose is lively and his work informed by recent headlines....[He] navigates rough terrain without being overly technical or sensational--two common pitfalls of writers who take on cybercrime and security. All this helps to explain Schneier's long-standing cult-hero status, even--indeed, especially--among his esteemed hacker adversaries." - John Simons 09/05/2000

Salon
"The solutions [in this book] are a nice, moderately upbeat touch, but the horror stories are the real draw--SECRETS AND LIES is more thriller than primer. Schneier crafts scary tales that deftly avoid a Chicken Little tone." - Brendan I. Koerner 08/31/2000


  
Product Image


Suggestion Box
Every voice counts, so stand up and be heard! Your opinion is important to us. If you have spotted a typo, discovered an incorrect price, or encountered a technical issue on this page, we want to hear about it. Thanks again for your feedback, and happy shopping! Please note: we are unable to reply directly to suggestions.
For additional information, click here to visit our Help Center.
Quick Help My Account What are you looking for? Country