> (As I've said many times, security breaches reported at
> conferences full of security people don't count as a
> predictor of what's out in the real world as a threat.
> But, it makes for interesting reading and establishes
> some metric on the ease of the attack.  iang)

I also recommend the brief discussion between Marcus Ranum and
Bill Cheswick on the very same topic in the aftermath of the
recent USENIX Security Symposium:



