On Wed, 9 Jul 2003, David Boyes wrote: > I don't deny that encryption is *good*. The question was whether it is > *necessary* in an environment where most of the common attacks you mention > are difficult or impossible to perform if the administrator is even > moderately alert.
It seems to me that society generally is confusing risk control (relatively easy and cheap) with risk elimination (neither easy nor cheap). Consider, for a familiar non-IT, the recent SARS outbreak. People chose not to travel, took extreme (and probably ineffective) countermeasures such as masks (effective, I read, for about 20 minutes). The cost was considerable inconvenience for those who didn't travel, for those who were supposed to meet them and considerable economic harm to people in Canada, China, Taiwan and Hong Kong, and worse, in places completely unaffected. Bees kill more people. Of course, determining realistic risks is never easy, and when you overlook something possibly predictable (such as aircraft flying into the WTC buildings), people will blame, even though their own predictive skills are no better. -- Cheers John. Join the "Linux Support by Small Businesses" list at http://mail.computerdatasafe.com.au/mailman/listinfo/lssb Copyright John Summerfield. Reproduction prohibited.
