On Wed, 9 Jul 2003, David Boyes wrote:

> I don't deny that encryption is *good*. The question was whether it is
> *necessary* in an environment where most of the common attacks you mention
> are difficult or impossible to perform if the administrator is even
> moderately alert.

It seems to me that society generally is confusing risk control
(relatively easy and cheap) with risk elimination (neither easy nor
cheap).

Consider, for a familiar non-IT, the recent SARS outbreak. People chose
not to travel, took extreme (and probably ineffective) countermeasures
such as masks (effective, I read, for about 20 minutes). The cost was
considerable inconvenience for those who didn't travel, for those who
were supposed to meet them and considerable economic harm to people in
Canada, China, Taiwan and Hong Kong, and worse, in places completely
unaffected.

Bees kill more people.

Of course, determining realistic risks is never easy, and when you
overlook something possibly predictable (such as aircraft flying into
the WTC buildings), people will blame, even though their own predictive
skills are no better.



--


Cheers
John.

Join the "Linux Support by Small Businesses" list at
http://mail.computerdatasafe.com.au/mailman/listinfo/lssb
Copyright John Summerfield. Reproduction prohibited.

Reply via email to