Online Security Authority has published a post dedicated to Security and Network Vulnerability Assessment, and it contains a very important mention on relationship between security issues and human beings nature: trust is the essence of all the area where security issues are involved.
Cyber-criminal would have to search another job, could they not rely on two big “friends”, goes the mentioned post. Human nature, with its traits of trusting, negligence, credulousness, ad curiosity is surely the strongest leverage in any hacker’s arsenal. Even in a world of advanced technology, hackers will use human weakness to unveil otherwise secure doors. However, technology is not perfect and telecom systems offer several opportunities to be exploited. These technical flaws are known as vulnerabilities.
Vulnerabilities in the whole World Wide Web are exploited all the time to attain control of computers and the complete networks and gain access to confidential data. Those network vulnerabilities can be found everywhere, but specifically in the web browsers and their plug-ins; in web servers and application software; and also in core equipments of the underlying network infrastructure of the Internet.
Unluckily, the host of the security coercion doesn’t end here. Big flaws can be found and exploited in several areas such as office programs, all operating systems, network device, mobile devices platforms and applications, to name a few.
These entire technical flaws give hidden doors that can be utilized to find a way around your security software, and “drop” a small program, which will “hook” your computer to a particular Botnet. Once captivated, your system will not show any problem and might even go unobserved to your existing antivirus and firewall software. In reality, that is the key aim of high-calibre hacker: to form a perfect piece of software, able to invisibly land and plant itself deep into a computer system, but ready to be activated when needed.
Trust, reputation, habits: these three entities should be taken into account when devising security-related tools and means to oppose the cyber-threats nowadays. It is also important to handle any security risk involved situation without disrupting any end user's trust to products and services they were using: even if the problem was caused by user's lack of competence and/or vulnerabilities found in a piece of software or service, curing should not be worse that the disease.
People are easily manipulated when they see names and trademarks they rely upon. These trust exploits should not result in generating negative effects, mainly the distrust. All the products and services may have flaws, security holes are routinely found in many a piece of software because Internet changes and evolves and social engineering may compromise even the strongest and most secure product- by attacking its users, the weakest link in all security systems.