|

User-friendliness vs. security - really a compromise?

In system development, the struggle is an old, perennial problem. User-friendliness is often the top priority for new commercial projects. But without the appropriate security, nothing works - public attention is increasingly focused on data security.

At the same time, the market is expecting a flood of affordable, easy-to-use and convenient networked devices as part of the Internet of Things (IoT) revolution. This poses particular challenges for the developers of embedded systems.

Security in the age of IoT

Nowadays, a smartphone is in every trouser pocket and so-called "wearables", i.e. accessories worn on the body with embedded systems, are becoming increasingly popular. Fast networking via modern Internet technologies has arrived everywhere. Even the average home will soon be filled with embedded systems that fulfill a wide variety of functions.

Convenience, Entertainment, automation, monitoring and security are aspects that will be increasingly used by new developments in the Internet of Things and Smart Home will increasingly find application.

Essentially, this means that one aspect is added to the necessary security during the development of commercial devices - namely the software. In addition to functional security, there is also IT security. The lion's share of these devices will also be networked, many of them wirelessly. The fact that not many of them are currently equipped with permanently integrated security aspects, represents a major risk.

Also, even if security functions have already been considered, a device can still still become a risk factor in the future. With the further embedded systems become more widespread, attacks will become increasingly attractive, which will inevitably lead to the emergence of even more unforeseen attack methods. We do not yet know what these look like, but it is almost certain that they will come. will come.

Consumers have become increasingly accustomed to comfort

Users of digital systems have increasingly moved away from specialists with in-depth specialist knowledge. This is a completely natural development in the context of the spread of personal gadgets: computers are no longer extremely expensive devices for enthusiasts with an interest in programming. The more widespread a technology becomes - and in the context of comprehensive digitalization since the 1990s, digital systems really are everywhere - the lower the entry threshold has to be so that users of all kinds can use it without any problems.

Plug and play instead of individualization.

The Establishing a uniform security standard throughout the entire network for all possible applications is therefore no longer realistic for many no longer realistic for many users. The design of the user software, where the trend is towards convenience and intuitive intuitive usability, has pushed comprehensive influence on functions and settings and settings into the background. Plug and play instead of individualization.

Usability vs Security Tradeoff

There are There are therefore three factors that need to be considered when realizing a product must be taken into account when developing a system. Many are of the opinion opinion that these factors are fed by common resources resources:

  • Usability: The simplicity with which a system can be used. Highly simplified processes that are only designed for convenience, reduce security.
  • Security: The security of the system. Increased security increases the complexity increases, which reduces usability.
  • Customizability: The extent to which experienced users can customize the user experience customize the user experience to their liking. As expertise is required for the correct settings is required, usability suffers.

So the basic assumption is: The more you maximize usability as a developer, the maximize usability, the greater the risk that security will suffer. security suffers. Imagine the example of a car, a car that automatically unlocks audibly when the key is nearby. is nearby. Of course, this increases convenience enormously, but drivers the control to leave the car locked for safety reasons, even even when they are in the vicinity.

Another problem is that, regardless of the security functions implemented, the human factor is still an interface that continues to represent a security risk. For this reason, convenience has often had to be sacrificed in the past so that users do not put themselves at risk. Just think of typical password requirements for programs and web applications - if these did not exist, the password would be Password123! is almost certainly widespread.

Similarly, the security expected by users is a big factor in their tolerance for security features that limit the convenience of use. Systems associated with online banking are a good example of an area in which no user is immune to multiple passwords, the need for 2-factor authentication and TANs will be negatively surprised.

For However, this will not be the case for most typical IoT end devices. be the case. This can lead to end users not valuing the security factor factor as important because they are not aware of the attack possibilities. In these cases, an increasing security through functions that are invisible to users is the first step - for example with end-to-end end-to-end encryption for communication apps.

Security by Default as a good step

A good way to ensure the ease of use of all possible devices devices without negatively impacting security is the Security by Default is the security by default standard. This means that without any necessary influence or specific setting, a system system is already set to the most secure mode of operation in the the most secure mode of operation.

The lawyers who drafted the General Data Protection Regulation (GDPR) have this standard made the status quo with regard to the use of personal data. The same applies to the security of IoT end devices. The standard use of WPA2 for networked devices of all kinds, for example, is a necessary step to prevent the creation of insecure networks.

But there is always the possibility that users will select non-recommended settings and thereby create a risk. Should you restrict customizability so that only the standard standard settings can be used? There is a more elegant solution.

Security by Design as a solution

All risk factors, both those of attackers and those of users, are prevented from the outset if the embedded systems are developed from the ground up with security as a maxim. A deeply implemented E2EE is the foundation for securely designed systems. Due to the growing popularity of cloud-based systems, data transmission in particular is an important factor.

System developers should therefore understand security as a fundamental feature of a system. of a system. With well-designed embedded security, users are relieved, can be provided with a high level of usability and are eliminated as risk factors.

For some currently popular networked products, use cases are quite clearly clearly limited, which naturally makes operation very convenient according to the KISS principle. naturally becomes very convenient. It should therefore not be too challenge to integrate such devices - such as a smart smart loudspeaker - with a focus on security right from the start of development. security right from the start. Only really necessary aspects of the system should therefore be taken into account in the software so that the potential for risks to arise are minimized.

With devices of the first generation, such procedures were may have been avoided for cost reasons. But for two reasons reasons, it is likely to soon become an industry standard:

  • It is cheaper in the long term for companies that remain in the industry to design their IoT devices securely from the outset than to react to problems that arise.
  • When users are sensitized, security becomes a selling point. The more protected devices are preferred.

Apple has already shown with the introduction and marketing of its T2 chip demonstrated that hardware-based encryption can be justified today and can already be justified today and communicated to customers accordingly. customers accordingly. Security functions that operate at hardware level will certainly play a certainly play a role in the future of IoT.

It is therefore advisable for developers to look into the implementation of security by design in the future, particularly via the underlying architectures of the systems.

Author: Benjamin Krapf studied Applied Computer Science in Düsseldorf. He has been working as a system developer at a large German software company for four years and is interested in news on the embedded systems market in his spare time.

Image sources: Title: Tierney / Picture 2: vanillya - both fotolia.com

Similar Posts

Leave a Reply