{"id":2263,"date":"2019-07-11T08:00:15","date_gmt":"2019-07-11T06:00:15","guid":{"rendered":"https:\/\/se-trends.de\/?p=2263"},"modified":"2019-07-10T13:43:54","modified_gmt":"2019-07-10T11:43:54","slug":"user-friendliness-vs-security","status":"publish","type":"post","link":"https:\/\/www.se-trends.de\/en\/nutzerfreundlichkeit-vs-sicherheit\/","title":{"rendered":"User-friendliness vs. security - really a compromise?"},"content":{"rendered":"<p class=\"wp-block-paragraph\">In system development, the struggle is an old, perennial problem. User-friendliness is often the top priority for new commercial projects. But without the appropriate security, nothing works - public attention is increasingly focused on data security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the same time, the market is expecting a flood of affordable, easy-to-use and convenient networked devices as part of the Internet of Things (IoT) revolution. This poses particular challenges for the developers of embedded systems.<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">Security\nin the age of IoT<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nowadays, a smartphone is in every trouser pocket and so-called \"wearables\", i.e. accessories worn on the body with embedded systems, are becoming increasingly popular. Fast networking via <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.verivox.de\/internet\/themen\/glasfaserkabel\/\" target=\"_blank\">modern Internet technologies<\/a> has arrived everywhere. Even the average home will soon be filled with embedded systems that fulfill a wide variety of functions.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Convenience,\nEntertainment, automation, monitoring and security are\naspects that will be increasingly used by new developments in the Internet of Things and\nSmart Home will increasingly find application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Essentially, this means that one aspect is added to the necessary security during the development of commercial devices - namely the software. In addition to functional security, there is also IT security. The lion's share of these devices will also be networked, many of them wirelessly. The fact that not many of them are currently equipped with permanently integrated security aspects, <a href=\"https:\/\/www.se-trends.de\/en\/iot-security-a-tsunami-is-coming\/\">represents a major risk<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also,\neven if security functions have already been considered, a device can still\nstill become a risk factor in the future. With the further\nembedded systems become more widespread, attacks will become increasingly attractive,\nwhich will inevitably lead to the emergence of even more unforeseen\nattack methods. We do not yet know what these\nlook like, but it is almost certain that they will come.\nwill come. \n<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Consumers\nhave become increasingly accustomed to comfort<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Users of digital systems have increasingly moved away from specialists with in-depth specialist knowledge. This is a completely natural development in the context of the spread of personal gadgets: computers are no longer extremely expensive devices for enthusiasts with an interest in programming. The more widespread a technology becomes - and in the context of comprehensive digitalization since the 1990s, digital systems really are everywhere - the lower the entry threshold has to be so that users of all kinds can use it without any problems.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Plug and play instead of individualization.<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The\nEstablishing a uniform security standard throughout the entire\nnetwork for all possible applications is therefore no longer realistic for many\nno longer realistic for many users. The design of the\nuser software, where the trend is towards convenience and intuitive\nintuitive usability, has pushed comprehensive influence on functions and settings\nand settings into the background. Plug and play\ninstead of individualization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Usability\nvs Security Tradeoff<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are\nThere are therefore three factors that need to be considered when realizing a product\nmust be taken into account when developing a system. Many are of the opinion\nopinion that these factors are fed by common resources\nresources:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>\n<strong>Usability:<\/strong>\n\tThe simplicity with which a system can be used. Highly\n\tsimplified processes that are only designed for convenience,\n\treduce security.\n\t<\/li><li>\n<strong>Security:<\/strong>\n\tThe security of the system. Increased security increases the\n\tcomplexity increases, which reduces usability.\n\t<\/li><li>\n<strong>Customizability:\n\t<\/strong>The\n\textent to which experienced users can customize the user experience\n\tcustomize the user experience to their liking. As expertise is required for\n\tthe correct settings is required, usability suffers.\n<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So\nthe basic assumption is: The more you maximize usability as a developer, the\nmaximize usability, the greater the risk that security will suffer.\nsecurity suffers. Imagine the example of a car, a car\nthat automatically unlocks audibly when the key is nearby.\nis nearby. Of course, this increases convenience enormously, but\ndrivers the control to leave the car locked for safety reasons, even\neven when they are in the vicinity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another problem is that, regardless of the security functions implemented, the human factor is still an interface that continues to represent a security risk. For this reason, convenience has often had to be sacrificed in the past so that users do not put themselves at risk. Just think of typical password requirements for programs and web applications - if these did not exist, the password would be <a href=\"http:\/\/www.commitstrip.com\/en\/2018\/04\/27\/security-security-security\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Password123! (opens in a new tab)\">Password123!<\/a> is almost certainly widespread.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Similarly, the security expected by users is a big factor in their tolerance for security features that limit the convenience of use. Systems associated with online banking are a good example of an area in which no user is immune to multiple passwords, the need for <a href=\"https:\/\/www.computerweekly.com\/de\/definition\/Zwei-Faktor-Authentifizierung\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">2-factor authentication<\/a> and TANs will be negatively surprised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For\nHowever, this will not be the case for most typical IoT end devices.\nbe the case. This can lead to end users not valuing the security factor\nfactor as important because they are not aware of the\nattack possibilities. In these cases, an\nincreasing security through functions that are invisible to users is the\nfirst step - for example with end-to-end\nend-to-end encryption for communication apps.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security\nby Default as a good step<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A\ngood way to ensure the ease of use of all possible devices\ndevices without negatively impacting security is the Security by Default\nis the security by default standard. This means\nthat without any necessary influence or specific setting, a system\nsystem is already set to the most secure mode of operation in the\nthe most secure mode of operation. \n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The lawyers who drafted the General Data Protection Regulation (GDPR) have <a href=\"https:\/\/dsgvo-gesetz.de\/art-25-dsgvo\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">this standard<\/a> made the status quo with regard to the use of personal data. The same applies to the security of IoT end devices. The standard use of WPA2 for networked devices of all kinds, for example, is a necessary step to prevent the creation of insecure networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But\nthere is always the possibility that users will select non-recommended\nsettings and thereby create a risk. Should you\nrestrict customizability so that only the standard\nstandard settings can be used? There is a\nmore elegant solution.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security\nby Design as a solution<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-src=\"https:\/\/se-trends.de\/wp-content\/uploads\/2019\/07\/image-1024x430.png\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\" alt=\"\" class=\"wp-image-2264 lazyload\"\/><noscript><img decoding=\"async\" src=\"https:\/\/se-trends.de\/wp-content\/uploads\/2019\/07\/image-1024x430.png\" alt=\"\" class=\"wp-image-2264\"><\/noscript><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">All risk factors, both those of attackers and those of users, are prevented from the outset if the embedded systems are developed from the ground up with security as a maxim. A deeply implemented E2EE is the foundation for securely designed systems. Due to the growing popularity of cloud-based systems, data transmission in particular is an important factor.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">System developers\nshould therefore understand security as a fundamental feature of a system.\nof a system. With well-designed embedded security, users are\nrelieved, can be provided with a high level of usability and are\neliminated as risk factors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For\nsome currently popular networked products, use cases are quite clearly\nclearly limited, which naturally makes operation very convenient according to the KISS principle.\nnaturally becomes very convenient. It should therefore not be too\nchallenge to integrate such devices - such as a smart\nsmart loudspeaker - with a focus on security right from the start of development.\nsecurity right from the start. Only really necessary aspects of the system\nshould therefore be taken into account in the software so that the potential\nfor risks to arise are minimized.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With\ndevices of the first generation, such procedures were\nmay have been avoided for cost reasons. But for two reasons\nreasons, it is likely to soon become an industry standard:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>\nIt\n\tis cheaper in the long term for companies that remain in the industry\n\tto design their IoT devices securely from the outset than to\n\treact to problems that arise.\n\t<\/li><li>\nWhen\n\tusers are sensitized, security becomes a selling point.\n\tThe more protected devices are preferred.\n<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Apple\nhas already shown with the introduction and marketing of its T2 chip\ndemonstrated that hardware-based encryption can be justified today and\ncan already be justified today and communicated to customers accordingly.\ncustomers accordingly. Security functions that operate at hardware level will certainly play a\ncertainly play a role in the future of IoT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is therefore advisable for developers to look into the implementation of security by design in the future, particularly via the underlying architectures of the systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Author:<\/strong> Benjamin Krapf studied Applied Computer Science in D\u00fcsseldorf. He has been working as a system developer at a large German software company for four years and is interested in news on the embedded systems market in his spare time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"text-align:right\">Image sources: Title: <a href=\"https:\/\/de.fotolia.com\/id\/270945102\">Tierney<\/a> \/ Picture 2: <a href=\"https:\/\/de.fotolia.com\/id\/208530971\">vanillya<\/a>  - both fotolia.com<\/p>","protected":false},"excerpt":{"rendered":"<p>In system development, the struggle is an old, perennial problem. User-friendliness is often the top priority for new commercial projects. But without the appropriate security, nothing works - public attention is increasingly focused on data security. At the same time, as part of the Internet of Things (IoT) revolution, the market is expecting a flood of affordable, simple and...<\/p>","protected":false},"author":11,"featured_media":2266,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[72,5],"tags":[200,384,257,405,199],"class_list":["post-2263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fallbeispiel","category-funktionale-sicherheit","tag-angriffssicherheit","tag-eingebettete-systeme","tag-iot","tag-nutzerfreundlichkeit","tag-sicherheit"],"_links":{"self":[{"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/posts\/2263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/comments?post=2263"}],"version-history":[{"count":0,"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/posts\/2263\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/media\/2266"}],"wp:attachment":[{"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/media?parent=2263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/categories?post=2263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.se-trends.de\/en\/wp-json\/wp\/v2\/tags?post=2263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}