Learn about Zero Trust Architecture
Impenetrable cybersecurity without sacrificing usability
Gain detailed visibility into all your endpoints activities
Harden applications and hardware environments
Immediate and continuous response to incidents
Close the window of time your data could be exposed
Get your Comodo solutions setup, deployed or optimized
Control access to malicious websites
Defend from any internet based threats
Stop email threats before it enters your inbox
Preserve and protect your sensitive data
Keep your website running fast and malware free
Add encryption to your websites
Automated certificate mgmt. platform
Secure private intranet environments
Digital signature solutions for cloud apps
Encrypt emails for senders and recipients
Stay compliant with PCI DSS
Trusted authentication for IoT devices
Francisco Partners a leading technology-focused private equity fund, has acquired a majority stake in Comodo’s certificate authority business. Newly renamed from Comodo CA Limited to Sectigo Limited. Privacy Policies, Trademarks, Patents and Terms & Conditions are available on Sectigo Limited’s web site.
Meet the people behind the direction for Comodo
Get the latest news about Comodo
People are the key to achievement and prosperity
Stay up to date with our on-demand webinars
Worldwide: Sales, Support and General Inquiries
Schedule a live demonstration of our solutions
Need immediate help? Call 1-888-551-1531
Instantly removes viruses to keep your PC virus free
Experience true mobile security on your mobile apple devices
Secure Internet Browser based on Chrome
Chrome browser internet security extension
Submit a ticket to our support team
Share any product bugs or security flaws
Collaborate with research experts on data sets
Valkyrie Threat Intelligence Plugins
Valkyrie Threat Intelligence APIs
Sometimes life just doesn’t make sense. As humans, we are capable of creating and implementing so many remarkable things, and yet we often struggle to make the most basic connections. From the great pyramids of Egypt to the voyage of Apollo 11 to the theory of relativity, mankind has demonstrated the ability to craft innovations that go far beyond the obvious limitations of body and mind. Even more, they have proven their capacity to create solutions for every avenue of life, especially as it pertains to the advancement of their livelihood. But for some reason, organizations around the world are still struggling with many aspects of cybersecurity, from writing bug-free code to establishing effective regulations. True, the rules of cyberspace are different from those of the physical world—and yes, we are currently embroiled in an unprecedented digital revolution… And yes, the nodal nature of a lightning-fast network makes controlling its boundaries difficult, but still. Can’t we make computers easier and safer to use?
VP and Principal Scientist at Comodo Cybersecurity, Dr. Phillip Hallam-Baker, believes we can. This morning, in his RSAC 2018 presentation, Why Did We Make Security So Hard?, he approaches the subject with startling simplicity. Usability. “The only security application we can expect users to use is one that demands nothing from them.” We all know an easier computer interface equates to better cybersecurity, especially for those folks who don’t know the difference between a router and firewall, so perhaps the solution isn’t so elusive after all. Provide people with clear, efficient, and intuitive systems, and they will handle them more appropriately as a result. Of course, educating people is always a smart decision, but the truth is most of the population is far too busy trying to complete their own online work to sit and ponder the security of their network or their email or their social media. They have their own fish to fry, as it were.
As Hallam-Baker reminds us, “secure applications and their features usually don’t get used because they require the user to be thinking about security,” when what they want to be thinking about is buying a microwave on Amazon or meeting their boss’s deadline. So, while technological responses to cybersecurity are obviously critical, understanding the inherent responses of human users is equally as valuable. Why does someone need to go through 17 different steps to enable S/MIME encryption (and click an extra button every time a message is sent) when in theory the process could be completed with far less effort? The point is, they don’t. “We have to strip out all unnecessary steps in securing data and make encryption the default and not the exception.” Combining this simple approach with effective managed security services, like those implemented by Comodo Cybersecurity, is a sure-fire way to create systems that are both safe and highly usable.
As long as we continue to treat cybersecurity as just a technical problem, and not a design one, we will continue to fail. But if we can honestly address the results of usability testing—thereby defining the efficacy of our products, applications, websites, software packages, or devices—the goal of improved usability and security is fully attainable. By shifting our focus to the optimization of UI designs, work flows, and user understanding, we can learn more about how people and systems can come together to achieve real progress. The data collected from usability labs can provide engineers with ideas for future innovation that speaks to the need for improved security and human understanding. This effort includes identifying issues with products and paying attention to how users:
The bottom line is, computers are smart and can do a lot of the heavy lifting for us. So, why make usability hard on the user? Hallam-Baker tells us, “any instructions you can write for the user can be turned into code and executed by the machine,” which makes perfect sense. Handing over the more complex actions to the computer-side of the exchange is a far better option that establishing unrealistic expectations for people who won’t (and often can’t) meet them.
The hypothesis fleshed out through Hallam-Baker’s presentation asserts that is is possible to solve any security usability issue by introducing an additional layer of PKI. This set of roles, policies, and procedures supports the distribution and identification of public encryption keys and enables users and computers to securely exchange information over networks, thereby identifying the identity of the other part. Without this system, sensitive data could still be encrypted and shared but it could not confirm authorization. Digital certificates sit at the heart of PKI because they are what affirms identify of the certificate subject and binds that identity to the public key. As a solution layer, the Mathematical Mesh is a cloud repository for configuration data. Mesh tools pull configurations from the cloud and makes devices run properly with no user effort. This affects security because it automates the administrative process and implements security with minimal compromise and error. As a security tool, strong end-to-end encryption works internally to enable stronger application management of email, web, and SSH.
While this is not the only solution to the larger question of how to simplify usability, it provides clarity around just how feasible it would be to change the way we think about computers and how we interact with them. Yes, innovating new technology is always going to be an essential part of our digital evolution; however, strange as it sounds—we will likely never reach the stars if we don’t also remember our own limitations.
Tags: comodo,comodo news,Cyber Security
Reading Time: 4 minutes Increased dependency on computers and access to data makes an organization more vulnerable to cybersecurity threats. With the increase in cyber-criminals and cyber-attacks, many companies today are looking for greater protection of their decentralized computing work environments from their Managed Service Providers (MSPs). As a result, MSPs need to deliver firewall solutions that are designed…
Reading Time: 3 minutes Rapid technological growth and increasing digitalization in all aspects of life around the world have increased the value of ensuring cyber-security at all levels. This is increasingly true for EU member states and the organizations that are based in or operate from these countries. The number of cyber-attacks targeting EU member states has risen. The…
Reading Time: 3 minutes Disruptions are often unforeseen. This could be a catastrophic event like a hurricane, a fire, or an earthquake. Disruptions, however, can also come in other forms such as that of a pandemic. This means that a building doesn’t necessarily have to be demolished or lives have to be lost for an unforeseen event to completely…
Sign up to our cyber security newsletter
Comodo Cybersecurity would like to keep in touch with you about cybersecurity issues, as well as products and services available. Please sign up to receive occasional communications. As a cybersecurity company, we take your privacy and security very seriously and have strong safeguards in place to protect your information.
See how your organization scores against cybersecurity threats
Advanced Endpoint Protection, Endpoint Detection and Response Built On Zero Trust Architecture available on our SaaS EPP