We could ground all airplanes and not have any more airplane crashes, ... The key is whether the good uses of the Net outweigh the bad. Life is like that. You just have to take the good with the bad. |
We don?t have a field in the database system that will say you're an evildoer. |
We'd be crazy to assume that the bad guys aren't thinking of this. |
What will happen when the CFO looks at his premium and realizes that it will go down 50 percent if he gets rid of all his insecure Windows operating systems and replaces them with a secure version of Linux? The choice of which operating system to use will no longer be 100 percent technical, ... Microsoft, and other companies with shoddy security, will start losing sales because companies don't want to pay the insurance premiums. |
What you and I are saying is much less important than the fact that you and I are talking. Against traffic analysis, encryption is irrelevant. |
You can't defend. You can't prevent. The only thing you can do is detect and respond. |
You have something called ALE: average loss expectancy. You multiply the probability of an event happening with the amount of damage you'll incur, and that'll tell you how much to spend on security. When you deal with events that have a very, very high damage [amount], and a very, very low probability of occurrence, you multiply infinity by zero and get whatever you want. |
You have to make the entity in the position to solve the problem, responsible for the problem. Otherwise, it doesn't get solved. |