It is easy to determine who needs to develop a means of protecting information. These are people and organizations who have something to protect, ie, practically everything. Most of those in need, of course, are using technology protection by others, but in some cases, the information security are developed on its own. For the development of their defense makes sense to start in three cases: - protection system is being developed as commercial project - existing remedies are not able to provide the required functionality - existing remedies are not appropriate for security reasons. The first case where the protection is developed for profit, of little interest - this is an ordinary commercial project, in which good security may well not play any role.
The sole purpose of the developer - to make the most profits. In the second case the user needs to protect the information in some unique circumstances for which none of the existing system was not designed. Such situations arise regularly as a direct consequence of technological development. Until there were computers, did not need an encryption algorithm des. While not widespread mobile technology, was not required to implement persistent cryptographic algorithms on processors used in handsets. Development of new technologies in any field - a very risky, but information security risk is increased many times.
Risk are not only data processed in the period after the discovery of the mistake the enemy and to correct this error, but generally all the information that is protected at a time when there was an error. The third case is amusing that, despite the presence of security tools, apparently suitable for the task, there is no confidence in the reliability of existing solutions. And if the cost of loss of integrity or confidentiality & chnoy information is very high (Which is quite realistic, for example, banking information and state secrets), it makes sense to spend resources to develop its own security implementation. Since the U.S. once spent on the development of the algorithm des and rsa now feels calm. Indeed, to achieve a rational belief that the funds are sewn by someone else, do not include accidental or intended introduced vulnerabilities, it is very difficult.
Recent Comments