Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Security Analogies
Scott Granneman, 2007-05-29

The following is a written version of a speech I gave at The Open Solutions Summit (AKA LinuxWorld NY) in New York City in February. It's long, but I think you will find it interesting. If you want to get to the website I announced, jump to the last section.

Comments Mode:
Security Analogies 2007-05-29
Anonymous
Scaring people isn't working anymore 2007-05-31
Gordon Fecyk
To use an analogy: "The boy who cried wolf." Nobody believes a liar, even when they're telling the truth.

The only useful example there is the security checklist, and even that's way too long for the average person to read and digest.

As for the rest, "Time to dump Internet Explorer" and "Surprises inside Vista's EULA" are great examples of lies of ommission. "Time" misses the real problem (running as Admin) while "Surprises" forgets that Securityfocus' primary sponsor practices the same low-ball tactics as Microsoft.

If you want to get a security message across, stop writing long boring articles explaining bizarre middle-age examples and provide short, simpler and more modern analogies, such as car seat belts and power tool safety guards.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/445/34576#34576
Limitations to Security Analogies 2007-05-31
S Lo Presti
Security Analogies 2007-06-01
Anonymous
Security Similes. 2007-06-04
jreid
Security Analogies 2007-06-05
Vladimir
Security Analogies 2007-06-07
http://blog.purepistos.net
Security Analogies 2007-06-08
Anonymous (1 replies)
Re: Inconceivable! 2007-08-09
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus