Fort Knox is no model for the Internet
[Commentary] A few weeks ago PC security company McAfee released an update to its anti-virus software. For some customers, the update mistakenly destroyed a legitimate and crucial file in the Windows operating system. Hundreds of thousands of personal computers, perhaps millions, were rendered unusable. One university lost the use of 8,000 of its 25,000 PCs, and some affected hospitals turned away non-trauma patients from their emergency rooms. This debacle is an example of a structural failing in security that echoes across the entire Internet. We can call it the "Fort Knox" problem.
The famed US bullion depository offers security through centralization. Gunships, tanks, and 30,000 soldiers surround a vault containing more than $700bn in gold. But while such centralization is ideal for a government's bullion it is an awful model for Internet security. Traditionally, we have had decentralized security: if one PC is compromised, or one website fails, others will carry on. But in the past few years cyber attacks have leveraged their reach through increasingly sophisticated digital "bots", which crawl the web looking for computers and sites to compromise. Those with well-financed websites have spent enormous amounts on digital bunkers, while others simply hunker down. We have two things going for us that the real Fort Knox does not: we can copy our digital gold, and there are lots of us, each with our own stake in security and autonomy. First, back-ups can be made more routine and decentralized. Second, we can reinvigorate the Internet's principle of open, distributed architecture responsible for so much growth and innovation.
Fort Knox is no model for the Internet