by sjvn
Security

When is there too much security?

Adding layer after layer of security sometimes actually gets in the way of securing your computer.

5 comments | 20I like it!
October 26, 2009, 02:47 PM — 

I was recently surprised when someone asked me what anti-virus programs they should be running. Note, he said 'programs,' not program, and that's what he meant. He thought that if one A/V (anti-viral) program would do him good then two or three would be even better.

Ah.... no, that's not how it works.

While it's certainly true that one A/V program will catching something that another program might miss, if you add layers of A/V software to one PC, you're asking for the two of them to clash with each other. The end result is a PC that will certainly run slower, and might very well stop working from time to time because of conflicts between them.

You're much better off if you just get one good A/V program and keep it updated.

The same is also true with firewall and other security programs. Multiple layers of the same kind of protection on a single PC just means that there are more ways for things to go wrong, not better, added protection.

It's a different story if you're running a network. Even on a small network you should have firewalls both on your PCs and on your server or device that stands between you and the Internet, like a SONICWall TZ or NSA Series appliance. You'll still need to make sure that everything works smoothly together. I can't count the number of times I've found that an Internet program was 'broken' because while one firewall let the software access its required port, another blocked it.

Finding and fixing that kind of problem comes with a network administrator's job. With so much malware and automated network attacks on the Internet, you have no choice but to block potentially dangerous connections from both your network as a whole and on each individual PC.

I also run a different A/V program on my servers, especially my mail server, than I do on my PCs. Since I'm not running the programs on the same box, I avoid the problems of conflicting programs, while making sure that I don't miss any problems on the servers.

Here again though I'm not going to run multiple programs to do the same job on the same box. If you try that, workstation or server, you're just asking for trouble. And, after all, the entire point of using security software in the first place is to avoid trouble.

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Comments

When?

Too much security is when there's no single place to go and get a picture of where everything stands that doesn't require a geek to get it. A proper and effective security posture is one where a CEO can pull up a screen and decide for themselves if everything is AOK. Security is a process not a product.
| reply

Heard of HIPS?

Avira Antivir + ThreatFire + Firefox NoScript + Sandbox + VM = Not too much

Each has caught many baddies.

Also

-Take disk image backup of the OS regularly
-Run browser and email sandboxed or in a virtual machine
-Keep your most valuable data off the net

TF is one the least customizable HIPS out there, but recommendable just because of this: install it and it just works.
| reply

Couldn't aggree more.

Right now I am helping somebody that had Shaw put Shaw Secure on their Laptop. After the install failed they tried to get it uninstalled. This didn't work and now they could not access the internet though IE. When I look at it I found they had 2 firewalls + plus what Shaw Secure left behind and 3 AntiVirus. I am having a very tough time reverting the changes as even a system restore won't work and have verified that the hardware is good by Ubuntu Live CD. I have only got the mail programs and the Windows updates working.
| reply
peer-to-peer

Esther Schindler
If the comments are ugly, the code is ugly

claird
SVG a graphics format for 21st century

pasmith
Take Chrome OS for a test spin

Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?

sjvn
64-bits of protection?

jfruh
Android fragments vs. the iPhone monolith

mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive

 

Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace