> The reason I jumped on your post is because I strongly
> believe that in order for computer security to grow up and
> stop being an intellectual backwater - we need to apply a
> little science and attempt to accurately quantify what we
> are doing. That means no more analysts practicing
> proctological numerology, no more self-selected samples
> used in polls, no more proof by vigorous hand-waving.

The industry perhaps in worse shape then that, when marketing has taken
over it from the ground up so completely that if one actually did take
security serious and locked down their browsers, perhaps the most
exploited attack vector of the current decade, to the point they are
advised to, they'd not beable to cruise a single security site.

Ron DuFresne
admin & senior security consultant: sysinfo.com


Ron DuFresne
admin & senior security consultant: sysinfo.com

