Latest 6 Reviews Here is what people are saying about the Secrets and Lies : Digital Security in a Networked World
"Brilliant"
2009-08-26
- Reviewed By User: A21H5S32XC7VAW
I have read hundreds of books on INFOSEC related topics but this one takes the cake.
Schneier is a brilliant information security mind and his topics are as relavant to managment as they are to INFOSEC professionals.
"The most comprehensive book on the subject of digital security"
2009-07-12
- Reviewed By User: A1TFFCKP0N2MUN
Its the most comprehensive and well-written book on the extensive subject of digital security. It carefully explains all the paradigms of security involved and then discusses the technologies and strategies employed to tackle them. Its laced with all the real world examples of security flaws and practices. It does a great job in keeping the reader interested in this subject.
This is a great book for those interested in security. The author does a great job at making the subject understandable and covers covers a great breadth of topics. A lot of the material covered is similar to a high level view of what's in CCISP books. The book's goal is to make you aware and to teach you how to think about security. Many times, companies will come up with a new product that they claim will take care of all your security problems for a stiff price. Understanding how to think about security will make you aware that there is no silver bullet. Instead, you need to follow a process to minimize the risk. This book is definitely worth reading.
I bought this title as a bundle with "Applied Cryptography" and "Practical Cryptography". I still need to read those 2 titles, but I have read "Secrets and Lies" (SL) cover to cover. My approach to reading this was that SL was that I would read the theory behind the security to start my studies on security, hacking, and cryptography. And this is just what this book is: an description of security. It is sort of like reading a book on math that describes the beauty of math, but does not list the math or have any problems for the reader to do. The reader learns the history, types of math, and interesting facts on how math can solve problems, but for further study is going to have to get a book with math problems. So the reader shouldn't expect this book to be a tech manual.
I really like this book because it shows how to think about security. The whole book is on this subject, but an example would be when he describes security in layers. He states that prevention attacks will fail, because you can't defend against every attack. So you need an instant alert that tells when you are under an attack. The sooner you know about the attack the faster you can respond. So that is prevention, detection, and response.
A weakness in prevention is people pick wrong passwords, freely give information, and don't understand the security measures. So no matter how strong you security is it is only as strong as the weakest link. Strong encryption may do well against brut force attacks, but attackers cheat. They find ways of getting around the encryption.
An example is an encrypted telephone. It would take a lot of knowledge, but if a Denial of Service attack was done on the encrypted line so the phone didn't work the "people" are going to use a regular line which can be eavesdropped on.
The book has thousands of ideas. Many much profound that is. Now that I read it, in the future I will reread sections to see what I have learned in my self-study.
Excellent book. A must read for any IT professional. The first 1/3 of the book is a little slow to get going for those already familiar with security concept such as CIA.
Last updated: Nov 21, 2009 at 18:48 EST. Pricing information is provided by the listed merchants. GoSale.com is not responsible for the accuracy of pricing information, product information or the images provided. Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on amazon.com or other merchants at the time of purchase will apply to the purchase of this product. As always, be sure to visit the merchant's site to review and verify product information, price, and shipping costs. GoSale.com is not responsible for the content and opinions contained in customer submitted reviews.