I was cleaning out my office last weekend and found a stack of conference proceedings from 2004 and 2005. Reading through the keynote abstracts and session descriptions was an exercise in humility. So many promising ideas. So many confident predictions. So many technologies that were going to transform enterprise security. Looking at them four years later, most of them never got beyond the proof-of-concept stage.
Here is my list of great stuff that never happened - or at least has not happened yet.
Trusted Computing Goes Mainstream
The Trusted Computing Group has been working on hardware-based security since 2003. The Trusted Platform Module was going to create a hardware root of trust in every PC, enabling secure boot, hardware-based attestation, and a foundation for digital rights management that could not be circumvented by software attacks.
Five years later, TPMs ship in most enterprise laptops and many desktops. The percentage of organizations actually using them for anything meaningful? Vanishingly small. BitLocker on Windows Vista uses the TPM for key storage, which is a genuine use case, but the broader vision of attestation-based trust - where a remote party can cryptographically verify the software state of your machine before granting access - remains largely unrealized.
The reasons are familiar: complexity, interoperability problems, and a lack of compelling applications that justify the implementation effort. Also, the association with DRM gave trusted computing a reputation problem in parts of the technical community that it has never fully shaken.
NAC Solves the Endpoint Problem
When NAC first emerged as a product category around 2004, the promise was enormous. Every device connecting to the network would be authenticated, assessed for compliance, and granted appropriate access based on its health and the identity of its user. Noncompliant devices would be automatically quarantined and remediated. Unauthorized devices would be blocked entirely.
Four years and several hundred million dollars in venture capital later, NAC adoption remains modest. The technology works in controlled environments and specific use cases - guest access being the most successful - but the vision of universal, policy-driven access control across the entire enterprise has proven far harder to implement than the early demos suggested.
The problem was never the technology. It was the operational complexity. Enterprises have heterogeneous networks with dozens of device types, multiple operating systems, legacy applications that break when you change the network topology, and users who have zero tolerance for being quarantined. Deploying NAC in enforcement mode across a large enterprise is a multi-year project that requires cooperation from networking, security, desktop support, and application teams. Most organizations underestimated that effort by an order of magnitude.
Federated Identity Eliminates Passwords
The Liberty Alliance, SAML, WS-Federation - the federated identity standards were going to solve the password problem once and for all. Users would authenticate once to their home organization and then access services across organizational boundaries using standards-based assertions. No more passwords. No more separate accounts. Single sign-on across the internet.
We have made some progress here. SAML-based SSO is widely deployed within enterprises for internal web applications. Some cross-organizational federation exists, primarily in higher education and government. But the grand vision of a universal identity federation that eliminates passwords for consumer-facing services? Not even close. Most people still have dozens of username-password combinations, and the rise of SaaS applications is making the problem worse, not better.
DRM That Works
Digital rights management was supposed to give content owners granular control over how their digital assets were used, copied, and distributed. Microsoft invested heavily in Windows Media DRM. The recording industry pushed for DRM on digital music downloads. Enterprise DRM products promised to protect sensitive documents from unauthorized copying and distribution.
The consumer DRM story ended when Apple removed DRM from iTunes in January of this year, essentially acknowledging that DRM created more friction for legitimate customers than it prevented piracy. Enterprise DRM remains a niche product used in specific high-security environments but has not achieved broad adoption. The user experience penalty is too high and the determined insider can always find workarounds.
The Common Thread
What all of these technologies share is a gap between theoretical elegance and operational reality. Each one makes perfect sense in a conference presentation. Each one addresses a real and important problem. And each one founders on the same rocks: implementation complexity, interoperability challenges, user friction, and the stubborn heterogeneity of real enterprise environments.
This is not an argument against innovation. It is an argument for humility in our predictions and realism in our deployment expectations. The next time a vendor tells you their technology is going to transform your security posture, ask them how many production deployments they have at enterprises your size. The answer is usually more illuminating than the demo.