{"id":16402,"date":"2015-04-14T20:04:43","date_gmt":"2015-04-14T20:04:43","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/"},"modified":"2026-08-08T17:53:01","modified_gmt":"2026-08-08T17:53:01","slug":"the-user-knows-nothing-rethinking-cybersecurity","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/","title":{"rendered":"The user knows nothing: Rethinking cybersecurity"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Claude Shannon, a WWII era mathematician and cryptographer, is considered by some to be the godfather of modern computing and cybersecurity. Among his many accomplishments, he developed what became known as Shannon&#8217;s Maxim: the enemy knows the system. (This is a derivation of Kerckhoffs&#8217; Principle, &#8220;the enemy knows everything,&#8221; coined by 19<sup>th<\/sup> century Dutch cryptographer Auguste Kerckhoffs.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This position \u2014 that the adversary knows your system as well as you do, if not better, as soon as it is stood up \u2014 while extreme, led to the creation of large number factorization, the basis for all modern encryption, from PGP to RSA tokens. Under these encryption schemes, as long as the key is kept private, someone can know everything about how the security system works and still not be able to crack it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To get to a place of true cybersecurity, another stark innovation in thinking is needed. What is needed is an Inverse Shannon&#8217;s Maxim: the user knows nothing.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"841\" src=\"\/wp-content\/uploads\/2026\/08\/635748094727240108-kamidrones-title-av-switchblade-comp-final-copyjpg.jpg\" alt=\"\" class=\"wp-image-12433\" srcset=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635748094727240108-kamidrones-title-av-switchblade-comp-final-copyjpg.jpg 1000w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635748094727240108-kamidrones-title-av-switchblade-comp-final-copyjpg.jpg?resize=300,252 300w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635748094727240108-kamidrones-title-av-switchblade-comp-final-copyjpg.jpg?resize=768,646 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;The area where we continue to have to do more work is on the human side, in terms of individuals doing things they should not do or a process failing,&#8221; Veterans Affairs CIO Stephen Warren said during a discussion on agency security in November.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The agency was able to block or effectively mitigate all cyberattacks, however lost access cards and misplaced data led to significant leakage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To create a truly secure network, systems can no longer rely on users to do the right thing at all times. Mistakes and poor behaviors will be made \u2014 someone will click when they shouldn&#8217;t, use &#8220;qwerty&#8221; as their password, or leave their laptop, unlocked, in a coffee shop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While agencies and organizations scramble to educate employees on the latest in cyber hygiene, others are working on cybersecurity measures that don&#8217;t require the user to have any specialized knowledge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Something-you-know, something-you-have<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jeremy Grant, a senior executive for identity management at NIST, known as an ardent advocate of the &#8220;kill the password&#8221; movement, has two-factor authentication on his phone without having to remember a thing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The something-he-knows \u2014 the passcode to gain access \u2014 is his thumbprint, read through a biometric scanner. The something-he-has \u2014 the authentication level, usually covered by a CAC or PIV card \u2014 is handled with derived credentials already on his phone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;This is the most secure solution that&#8217;s out there that&#8217;s standards-based that responds to how the market&#8217;s evolved,&#8221; Grant said.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"960\" height=\"686\" src=\"\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg\" alt=\"\" class=\"wp-image-16032\" srcset=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg 960w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg?resize=300,214 300w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg?resize=768,549 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;The most secure solution that nobody wants to use doesn&#8217;t really improve security at all. So focusing on usability is a key guiding principle,&#8221; he said. &#8220;Focus more on how we can get somebody like my dad, who is a 71-year-old retiree in Detroit doing a lot of stuff everyday on an iPad, what&#8217;s he going to be using? That&#8217;s where the market needs to go.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Biometrics and one-time passcodes do a good job of managing authentication without relying on the user to remember a password or navigate a labyrinth of checks. However, that method only deals with access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>&#8216;A clicker in every crowd&#8217;<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is almost impossible to stop malware from infiltrating a network if the adversary is persistent and creative. Modern hacking techniques rely less on direct intrusion and more on retrieving passwords and other key strokes that will allow malicious actors to gain access through accepted avenues, pretending to be an authorized user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is often done through spear-phishing \u2014 carefully crafted emails or social media that get a user to click through to a malicious site or download malware through a disguised attachment.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"960\" height=\"686\" src=\"\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg\" alt=\"\" class=\"wp-image-16032\" srcset=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg 960w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg?resize=300,214 300w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg?resize=768,549 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Getting a user to click can be as easy as sending a Tweet with a harmless looking link or, as in one instance, an email with a spreadsheet purportedly listing bonus payouts for everyone in a department.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Training employees not to fall for these scams is important but at some point, someone in every organization will get fooled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We realized seven years ago that you can&#8217;t stop spyware from getting on a computer,&#8221; Waller said. &#8220;To protect the user, you need to protect what they enter at the point of contact.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To do this, Strike Force has developed a key stroke encryption system that secures every character as it&#8217;s typed, pushes it through the application and decrypts on the screen in real time. Even if spyware is embedded in a device, any exfiltrated data would be encrypted and useless without the key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;This would have stopped what happened at Home Depot, Target, JP Morgan and every other breach in the last few years,&#8221; Waller asserted.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"3421\" height=\"2914\" src=\"\/wp-content\/uploads\/2026\/08\/635646235524228659-fed-malware-2jpg.jpg\" alt=\"\" class=\"wp-image-47593\" srcset=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646235524228659-fed-malware-2jpg.jpg 3421w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646235524228659-fed-malware-2jpg.jpg?resize=300,256 300w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646235524228659-fed-malware-2jpg.jpg?resize=768,654 768w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646235524228659-fed-malware-2jpg.jpg?resize=1024,872 1024w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646235524228659-fed-malware-2jpg.jpg?resize=1536,1308 1536w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646235524228659-fed-malware-2jpg.jpg?resize=2048,1744 2048w\" sizes=\"auto, (max-width: 3421px) 100vw, 3421px\" \/><figcaption class=\"wp-element-caption\">Winner hoax concept.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><span>Expecting perfect cyber hygiene from everyone on the enterprise at all times is unrealistic.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span>Photo Credit: Getty Images\/iStockphoto<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Strike Force has been working on a mobile solution in the form of a software developer kit, which it expects to roll out in the next few weeks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The kit will give application designers the tools to build key stroke encryption directly into their apps, shielding data entry from the device&#8217;s data dictionary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, key stroke encryption only protects against spyware. More destructive kinds of malware can wreak havoc on systems, wiping databases or blocking access until a ransom is paid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Distributed defense<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current methods like containerization \u2014 in which apps are segregated from an operating system, preventing the spread of infection \u2014 and sandboxing \u2014 &#8220;detonating&#8221; potentially malicious code in a safe environment \u2014 are making it harder for malware to infiltrate systems, but they&#8217;re not perfect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We&#8217;re seeing a dramatic uptick in SSL encrypted malware,&#8221; said John Gordineer, director of Dell&#8217;s SonicWall security system. &#8220;So the attackers are starting to use the same technology that the good guys use to protect things \u2014 they&#8217;re using it to protect their ability to conduct their business, which is stealing our money.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This shift in tactics by the adversary causes a number of new problems for firewalls. Now, an enterprise can no longer trust encrypted traffic coming into the network and resources have to be allocated to decrypt everything in a safe environment to be analyzed before passing the data along to the network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gordineer likened this to performing a man-in-the-middle attack on your own people.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"960\" height=\"686\" src=\"\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg\" alt=\"\" class=\"wp-image-16032\" srcset=\"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg 960w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg?resize=300,214 300w, https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635780001374134044-nav-pinning8jpg.jpg?resize=768,549 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">While this takes a lot of computing power, the system is automated and doesn&#8217;t rely on the employee to decide whether incoming traffic is suspicious or not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One way to get around the load problem is to distribute the work across multiple devices, as is done with Dell&#8217;s Invincea platform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Invincea takes that to a micro level,&#8221; Gordineer said. &#8220;Instead of trying to manage it all through one big sandbox, you&#8217;re distributing that out and each client, each laptop is responsible for doing zero-day prevention.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This solution will work for a time, until the bad actors develop a new way to slip past an organization&#8217;s firewalls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We&#8217;ve got to really be more sophisticated and more literate&#8221; about cybersecurity, said Paul Christman, vice president of public sector for Dell Software, noting it&#8217;s incumbent on the technology suppliers to stay abreast of developments on behalf of the users. &#8220;There&#8217;s nothing that kills a conversation at a cocktail party like encrypted network traffic \u2014 nobody cares. They just want [to order] their pizza and have their credit card information stored safely.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The users just want it to work. In an ideal world, the user knows nothing.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>True cybersecurity requires a new way of thinking \u2014 an Inverse Shannon&#8217;s Maxim.<\/p>\n","protected":false},"author":7,"featured_media":47587,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":15,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[15],"tags":[],"coauthors":[2349],"class_list":["post-16402","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-management"],"acf":{"subheadline":"","legacy_arc_id":"57WHQPDAIJDXDEVL7ORVFM6Q7Q","arc_canonical_url":"\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The user knows nothing: Rethinking cybersecurity - Federal Times<\/title>\n<meta name=\"description\" content=\"True cybersecurity requires a new way of thinking \u2014 an Inverse Shannon&#039;s Maxim.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The user knows nothing: Rethinking cybersecurity\" \/>\n<meta property=\"og:description\" content=\"True cybersecurity requires a new way of thinking \u2014 an Inverse Shannon&#039;s Maxim.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2015-04-14T20:04:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T17:53:01+00:00\" \/>\n<meta name=\"author\" content=\"Aaron Boyd\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aaron Boyd\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"The user knows nothing: Rethinking cybersecurity\",\n\t            \"datePublished\": \"2015-04-14T20:04:43+00:00\",\n\t            \"dateModified\": \"2026-08-08T17:53:01+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/\"\n\t            },\n\t            \"wordCount\": 1229,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635646231279726243-fed-claude-shannonjpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Inside the Agencies\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/\",\n\t            \"name\": \"The user knows nothing: Rethinking cybersecurity - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635646231279726243-fed-claude-shannonjpg.jpg\",\n\t            \"datePublished\": \"2015-04-14T20:04:43+00:00\",\n\t            \"dateModified\": \"2026-08-08T17:53:01+00:00\",\n\t            \"description\": \"True cybersecurity requires a new way of thinking \u2014 an Inverse Shannon's Maxim.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635646231279726243-fed-claude-shannonjpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/635646231279726243-fed-claude-shannonjpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/2015\\\/04\\\/14\\\/the-user-knows-nothing-rethinking-cybersecurity\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Inside the Agencies\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/management\\\/\",\n\t                    \"ad_zone\": \"management\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"The user knows nothing: Rethinking cybersecurity\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The user knows nothing: Rethinking cybersecurity - Federal Times","description":"True cybersecurity requires a new way of thinking \u2014 an Inverse Shannon's Maxim.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/","og_locale":"en_US","og_type":"article","og_title":"The user knows nothing: Rethinking cybersecurity","og_description":"True cybersecurity requires a new way of thinking \u2014 an Inverse Shannon's Maxim.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/","og_site_name":"Federal Times","article_published_time":"2015-04-14T20:04:43+00:00","article_modified_time":"2026-08-08T17:53:01+00:00","author":"Aaron Boyd","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aaron Boyd","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"The user knows nothing: Rethinking cybersecurity","datePublished":"2015-04-14T20:04:43+00:00","dateModified":"2026-08-08T17:53:01+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/"},"wordCount":1229,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646231279726243-fed-claude-shannonjpg.jpg","articleSection":["Inside the Agencies"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/","name":"The user knows nothing: Rethinking cybersecurity - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646231279726243-fed-claude-shannonjpg.jpg","datePublished":"2015-04-14T20:04:43+00:00","dateModified":"2026-08-08T17:53:01+00:00","description":"True cybersecurity requires a new way of thinking \u2014 an Inverse Shannon's Maxim.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646231279726243-fed-claude-shannonjpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646231279726243-fed-claude-shannonjpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/2015\/04\/14\/the-user-knows-nothing-rethinking-cybersecurity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Inside the Agencies","item":"https:\/\/one.sightlinemg.com\/federaltimes\/management\/","ad_zone":"management"},{"@type":"ListItem","position":3,"name":"The user knows nothing: Rethinking cybersecurity"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/635646231279726243-fed-claude-shannonjpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/16402","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=16402"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/16402\/revisions"}],"predecessor-version":[{"id":16405,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/16402\/revisions\/16405"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=16402"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=16402"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=16402"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=16402"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}