See buying choices for this item to see if it's one of the millions that are eligible for Amazon Prime.

29 used & new from £1.01

Have one to sell? Sell yours here
 
   
Secrets and Lies: Digital Security in a Networked World
 
 

Secrets and Lies: Digital Security in a Networked World (Hardcover)

by Bruce Schneier (Author) "The world is a dangerous place ..." (more)
4.7 out of 5 stars See all reviews (22 customer reviews)

Available from these sellers.


4 new from £18.95 25 used from £1.01
Other Editions: RRP: Our Price: Other Offers:
Paperback £11.99 £8.99 47 used & new from £5.27

Customers Viewing This Page May Be Interested in These Sponsored Links

  (What is this?)
Challenges of IT Security
   www.ciozone.com    Learn how top CIOs and IT Leaders handle enterprise wide security 
Secure Patch Management
   www.shavlik.com    Large networks, easy setup, reports Shavlik HFNetChkPro Free Trial 
Think Defensive
   www.thinkdefensive.co.uk    Computer Security Consulting Firm. Penetration Testing Services. 
  
 

Customers Who Bought This Item Also Bought

Beyond Fear: Thinking Sensibly About Security in an Uncertain World

Beyond Fear: Thinking Sensibly About Security in an Uncertain World

by Bruce Schneier
4.2 out of 5 stars (6)  £15.19
Schneier on Security

Schneier on Security

by Bruce Schneier
5.0 out of 5 stars (1)  £11.99
Security Engineering: A Guide to Building Dependable Distributed Systems

Security Engineering: A Guide to Building Dependable Distributed Systems

by Ross J. Anderson
4.9 out of 5 stars (8)  £33.25
The Art of Deception: Controlling the Human Element of Security

The Art of Deception: Controlling the Human Element of Security

by Steve Wozniak
3.8 out of 5 stars (16)  £6.99
The Art of Intrusion: The Real Stories Behind the Exploits of Hackers, Intruders and Deceivers

The Art of Intrusion: The Real Stories Behind the Exploits of Hackers, Intruders and Deceivers

by Kevin D. Mitnick
4.2 out of 5 stars (5)  £13.49
Explore similar items

Product details

  • Hardcover: 432 pages
  • Publisher: John Wiley & Sons (5 Sep 2000)
  • Language English
  • ISBN-10: 0471253111
  • ISBN-13: 978-0471253112
  • Product Dimensions: 23.6 x 16.7 x 3.5 cm
  • Average Customer Review: 4.7 out of 5 stars See all reviews (22 customer reviews)
  • Amazon.co.uk Sales Rank: 141,670 in Books (See Bestsellers in Books)

    Popular in this category:

    #65 in  Books > Computing & Internet > Computer Science > Security > Cryptography & Encryption
  • See Complete Table of Contents

Product Description

Amazon.co.uk Review
At the moment, it seems that hardly a day passes without fresh news of some glaring Internet security breach; online banks, of all things, seem to be particularly vulnerable at the moment. All of which will come as no great surprise to network security cum cryptography guru, Bruce Schnier. His latest book, Secrets and Lies, paints a very gloomy overview of the true state of network security. Schnier, founder of Counterpane Internet Security, has some harsh words to say about the state of network security, though, to be fair, his criticisms are directed far and wide; not one scapegoat, (not even Microsoft) is singled out for special attention. Depressingly, the words "fundamentally flawed" crop up time and time again in this absorbing book.

Secrets and Lies is a thorough backgrounder in all aspects of network security, an extremely wide remit that stretches from passwords to encryption, passing through authentication and attack trees along the way. The book is divided in to three broad categories, The Landscape, which covers attacks, adversaries and the need for security; Technologies, which discusses cryptography, authentication, network security, secure hardware and security tricks; and concludes with Strategies, which looks at vulnerabilities, risk assessment, security policies and the future of security. Mercifully there's a dim light at the end of this tunnel and Schnier ultimately remains upbeat about maintaining computer security and details a way forward in his conclusion.

Although working in a necessarily techie environment, Schnier's book is surprisingly jargon-free and easy to understand, even if you're not au fait with the inner workings of TCP/IP--it's common-sense, practical style makes a potentially dense and arcane subject accessible by just about anybody. It's also bang up to date, which makes for a pleasant change. Secrets and Lies is never less than thought-provoking and should be essential reading for every network administrator in the land. Be afraid, be very afraid! --Roger Gann

The Economist, September 2000
"Instead of talking algorithms to geeky programmers, he offers a primer in practical computer security aimed at those shopping, communicating or doing business online - almost everyone in other words."

See all Product Description


Inside This Book (Learn More)
First Sentence
The world is a dangerous place. Read the first page
Explore More
Concordance
Browse Sample Pages
Front Cover | Copyright | Table of Contents | Excerpt | Index | Back Cover
Search inside this book:

Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product)
Check a corresponding box or enter your own tags in the field below
computer security
networking
information technology
it security
computer science
sysadmin - security
management
schneier
computer
bruce schneier

Your tags: Add your first tag
 

What Do Customers Ultimately Buy After Viewing This Item?


 

Customer Reviews

22 Reviews
5 star:
 (17)
4 star:
 (4)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.7 out of 5 stars (22 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
21 of 21 people found the following review helpful:
5.0 out of 5 stars Compulsory reading, 12 Jul 2001
By A Customer
The previous reviewer suggests that universities ought to base courses around this book. Well we are doing just that. Last year, Secrets and Lies was recommended reading, but now I have broken the cryptography and the security into two separate teaching streams and this book forms compulsory reading for the security stream (his Applied Cryptography is strongly recommended for the other stream).

This is an excellent book, very approachable, especially for undergraduates. Not ideally structured to be a text book, but then there's not many text books that you'd want students to read from beginning to end, every word. Our students even get to try out some of the defensive mechanisms on an isolated network, and this book tells them of many of the possible pitfalls to guard against, and gives them some idea of just how big and how important a job it is.

Look forward to a generation of security-aware computer science graduates, with a fair bit of help from Mr Schneier and his books!

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
15 of 16 people found the following review helpful:
5.0 out of 5 stars Comprehensive and entertaining, 26 April 2001
By A Customer
When the news broke that a Russian cracker had successfully broken into the computer systems of global banking giant Citibank and stolen $12 million, the message was clear: inadequate computer security can cost millions. In Citibank's case, it was not just the money that it lost to the hacker, but many millions more that was subsequently withdrawn by people fearful that their life savings might be at risk. And such incidents are just the tip of the iceberg if the anecdotal evidence presented by Bruce Schneier in Secrets & Lies is any guide. But the most dangerous perpetrators are not necessarily skilled Russian crackers, but the intelligence organisations of major industrialised countries, including America, Britain, China, France and Russia.

Although many are engaged in industrial espionage on behalf of indigenous industries - particularly the French and Chinese secret services, according to Schneier - for the most part, their targets are normally other governments. And often, as the book illustrates, private companies collude: "Crypto AG, a Swiss company, sells encryption hardware to a lot of Third World governments. In 1994, one of their senior executives was arrested by the Iranian government for selling 'bad' cryptographic hardware. When he was released from jail a few years later, he went public with the news that his company had been modifying their equipment for years at the request of US intelligence," says Schneier.

In the corporate world, many incidents such as the Citibank theft never see the light of day, but there are few bounds to the ingenuity of the enterprising cyber-criminal. One included a JavaScript trojan horse program in the description field of a 'product for sale' ad on eBay. In this way, he was able to collect login and password information from anyone that viewed his page.

Others routinely use tools such as L0phtcrack to break into password protected systems. Older networking protocols, that require only seven, case-insensitive characters, can be cracked in hours. "On a 400-MHz Quad Pentium II, L0phtcrack can try every alphanumeric password in 5.5 hours, every alphanumeric password with some common symbols in 45 hours and every possible keyboard password in 480 hours," says Schneier.

And although Microsoft Windows NT does boast 128-bit encryption, the encryption keys are protected by a password system. This means that it is considerably less secure than people think. Indeed, Microsoft is learning only very slowly about how to build strong security into its products. The most important lesson for vendors to follow, says Schneier, is that such measures should be developed openly, and the computer community at large encouraged to test them to the limits before widespread adoption.

As a result, thousands of virtual private networks deployed worldwide are based on Microsoft technology that is littered with security holes. That technology is Microsoft's point-to-point tunnelling protocol (PPTP). "[It's] badly flawed," says Schneier. "They invented their own authentication protocol, their own hash functions and their own key generation algorithm. Every one of these items turned out to be badly flawed," he says. "It wasn't until 1998 that a paper describing the flaws was published. Microsoft quickly posted a series of fixes, which have since been evaluated and still found wanting," warns Schneier.

The reader of Secrets & Lies could be forgiven for thinking that security is futile. Schneier certainly knows his subject inside out. He can not only write knowledgably about such complex subjects as cryptography, but can write strong encryption algorithms himself. Schneier co-authored the Twofish Algorithm, one of the five finalists in the competition for the Advanced Encryption Standard (AES). And his first book, Applied Cryptography, sold more than 130,000 copies worldwide.

Secrets & Lies promises to match such sales. It is comprehensive, puts computer security into a wider context and is illustrated with numerous examples. As a result, not only is it entertaining, but is likely to end up on the reference shelf of thousands of CIOs worldwide.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
7 of 7 people found the following review helpful:
5.0 out of 5 stars This book has a lot to offer !, 18 Jul 2002
By A Customer
This book isn't what I expected. I thought it would be like a detailed analysis of hacking techniques and vulnerabilities. Instead, Bruce takes an overall look at security and how it affects every aspect of our lives (e.g. smart cars, ATMs, etc.), of course focusing mainly on computer and internet security.

So, I was a little disappointed initially, but as I read on, I was impressed with the depth of knowledge presented with respect to security - as he explains how security is not just prevention (e.g. firewalls), but also about detection and response, which are equally important. Security is a process (not a product) and is a chain only as strong as the weakest link.

It's a great read, and he does discuss cryptography, password cracking - how most passwords are easily crackable (and how it's usually done) - including discussion about l0phtcrack. I really liked the way he included real life security disasters, which made it more interesting.

This book has made me much more aware of security issues and the importance of open source security testing. Highly recommend it.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars good book good service by Amazon
Nothing to add, good book and good service by Amazon, I'm very happy

Best Regards
--
Davide Sacca'
Published 2 months ago by Giovanni Davide Sacca'

5.0 out of 5 stars An fantastic read
This book is without a doubt my favourite IT book. Its an excellent read for both those involved in security and those who are not. Read more
Published on 7 April 2004 by Mr. J. Mason

4.0 out of 5 stars Good read for an average Internet user
The book is a nice and easy read for an average user of the Internet or a middle level manager looking for information on data security. Read more
Published on 19 Jan 2004 by dolce0109

5.0 out of 5 stars Info a-go-go
I've actually had to read this book for module on my university course (had the exam last week, think it went pretty well), and it's a shame that many people will likely avoid it... Read more
Published on 18 Jan 2004 by Mr. Jonathan Downs

5.0 out of 5 stars And I thought I was paranoid!
This book is amazing. 'Cryptography' huh? That just sounds way to complicated for me. This book is brilliantly written and there's a laugh on nearly every page. Read more
Published on 30 Oct 2003 by Samuel J Chapman

4.0 out of 5 stars Essential Reading for anyone interested in Security
I first tried reading the Authors other book, Applied Cryptography, but that was way too technical for my needs.
Then along comes this book, at just the right level. Read more
Published on 11 Oct 2003 by Keith Appleyard

4.0 out of 5 stars A good primer
This is the first book on the subject that I have read, and it is put together very well. It gives a view of security as a process with many angles for concideration and ideas... Read more
Published on 30 Jul 2003 by hydes77

4.0 out of 5 stars Make this book part of your library
The book is primarily about looking at security as part of an overall plan of action rather than dealing with specifics. Read more
Published on 8 Jun 2003 by Mole

5.0 out of 5 stars Not so technical
The book provides a view of security for people who a not so technical. So for technical people, it may be a bit boring to read, but if you have to talk security to your boss and... Read more
Published on 12 April 2003 by tryl33

5.0 out of 5 stars An absolute must for Network Security Analysts
This is one of the most outstanding technical books I have ever read. It is great ammunition against those in top level management who need holes punched in a firewall. Read more
Published on 30 May 2001

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]

   


Listmania!


Look for similar items by category


Look for similar items by subject


Feedback


Computer Security 2e

Computer Security 2e

"Computer Security is a book that will teach you what you don′t... Read more
£28.49

Find similar items

 

More From Bruce Schneier

Applied Cryptography: Protocols...

Applied Cryptography: Protocols...

"the definitive publicly available text on the theory and practice of... Read more
£42.50 £29.75

 

We've Got Converse

Converse
Stock up on your favourite styles with great deals on Converse shoes.

Shop Converse

 

Treat Someone

Amazon.co.uk Gift Certificates--available in any amount from £5 to £500 With an Amazon.co.uk Gift Certificate, you can get them what they want (even if you don't know what that is).

Learn more about Gift Certificates

 
Ad

Where's My Stuff?

Delivery and Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue Shopping: Top Sellers

amazon.co.uk Amazon Home
International Sites:  United States  |  Germany  |  France  |  Japan  |  Canada  |  China
Business Programs: Sell on Amazon  |  Fulfilment by Amazon  |  Join Associates  |  Join Advantage
Customer Service  |  Help  |  View Basket  |  Your Account
About Amazon.co.uk  |  Careers at Amazon
Conditions of Use & Sale |  Privacy Notice  © 1996-2009, Amazon.com, Inc. and its affiliates