On Fri, 14 Mar 2008 16:53:01 CDT, "John C. A. Bambenek, GCIH, CISSP" said:

> Since when did the requirement of 100% success become the bar that must be
> crossed for any policy?  If you really believed 100% effectiveness was
> required before anything was initiated, we'd have to give up on information
> security all together.

On the other hand, many infosec people have this aversion to expending lots
of effort solving the wrong "problem".  The problem they're *trying* to solve
is "block potentially racy sites like BoingBoing", when the problem they
*should* be solving is "parents complaining when their kid gets an eyeful".

Attachment: pgpb8evhvnmhv.pgp
Description: PGP signature

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Reply via email to