5:02 PM -- The security industry tends to be plagued by a lot of experts on yesterday's issues. In the last three or four years the industry has gravitated toward network security devices like IPSes, IDSes, security information management devices, and the like.
I've heard a lot of experts on those older issues talk about the recent Web application security vulnerabilities and browser issues with a bit of contempt in their voices. It's as if they find computer security to be less important than enterprise security, without really understanding that the two are completely correlated. The most common fallacy is that large companies feel they are protected because they have a firewall.
The modern enterprise no longer looks like an onion, it's far more complex.
Take a look at a modern enterprise network -- it is not only highly interconnected but it also has many entry points, the most frequently overlooked of which is the laptop. Laptops have a firewall and antivirus software on them, but does that actually protect them? More importantly do those small software applications protect your enterprise? Why should it matter?
I'll tell you why: Enterprises are treating laptops like firewalls, and those firewalls are easily circumvented.
These two distinct but related fallacies create a false sense of enterprise security. Really, your mobile employees are the most likely to introduce seemingly invisible holes in your network, and there is nothing your firewall can do about it. The same domain origin policy has been broken. Browser security can no longer be relied on when software firewalls and antivirus are helpless to protect your employees. Maybe gopher is looking like a good option right about now. Regardless, it's time to start looking to putting your users in their own DMZ, isolating any mobile users on their own subnets and hardening your Intranet.
More bad news: It's going to get worse before it gets better. The browser community is years away from fixing this issue, so until then it's best to harden the network as much as possible. Unfortunately, that often requires expertise that most companies don't have and can't afford, since good Web application security experts are extremely difficult to find and expensive.
I guess those Web application vulnerabilities and browser issues aren't as trivial as some people might have previously thought.