|
Posted by Gary L. Burnore on 10/21/07 20:01
On Sun, 21 Oct 2007 14:05:33 -0400, Jerry Stuckle
<jstucklex@attglobal.net> wrote:
>Gary L. Burnore wrote:
>> On Sat, 20 Oct 2007 22:05:13 -0400, Jerry Stuckle
>> <jstucklex@attglobal.net> wrote:
>>
>>
>>> Security is not about prevention,
>>
>> WHAT? What a complete and totally moronic thing to say, Jerry.
>>
>> Security is about many things of which prevention is one.
>>
>
>No responsible person in the security field will ever claim that.
I'm a responsible person in the security field and I claim that. I've
been taught that and I teach that. That being that many things make
up good security. Prevention is one part of security.
>
>There is no such thing as "prevention". That would indicate that
>something can't happen, which is impossible to do.
>
>For instance, banks have been trying to prevent robberies for hundreds
>of years.
Banks prevent you, as an employee, from seeing all the things
necessary to get your hand on the data of a user. Does it work all
the time, no. That's where forensics come in. But if you don't
prevent it at all, you open yourself (yourself being the bank) to
lawsuits from customers, fines from FICA and harassment from auditors
for SOX.
>At no time will a responsible security professional claim anything about
>preventing break-ins.
Right. That's why banks don't use firewalls, don't use encryption,
don't use secure keys, etc.
Stick with coding, J. You obviously know little about security.
--
gburnore at DataBasix dot Com
---------------------------------------------------------------------------
How you look depends on where you go.
---------------------------------------------------------------------------
Gary L. Burnore | ÝÛ³ºÝ³Þ³ºÝ³³Ýۺݳ޳ºÝ³Ý³Þ³ºÝ³ÝÝÛ³
| ÝÛ³ºÝ³Þ³ºÝ³³Ýۺݳ޳ºÝ³Ý³Þ³ºÝ³ÝÝÛ³
Official .sig, Accept no substitutes. | ÝÛ³ºÝ³Þ³ºÝ³³Ýۺݳ޳ºÝ³Ý³Þ³ºÝ³ÝÝÛ³
| ÝÛ 0 1 7 2 3 / Ý³Þ 3 7 4 9 3 0 Û³
Black Helicopter Repair Services, Ltd.| Official Proof of Purchase
===========================================================================
Navigation:
[Reply to this message]
|