The Six Dumbest Ideas in Computer Security

Simon Phipps found a nice writeup about the The Six Dumbest Ideas in Computer Security. What's really nice about it is the direct and honest content of the original post. Not too much not too little, still it covers everything that basic planning needs to address and also provides a good reasoning.

The six points are:

  1. Default Permit
  2. Enumerating Badness
  3. Penetrate and Patch
  4. Hacking is Cool[1]
  5. Educating Users
  6. Action is Better Than Inaction

[1] Yes I do think hacking is cool, unfortunately Marcus J. Ranum is right about it. The media reports about hacking make it cool personally I freak out a bit about the difference of hacking vs. cracking

2017-11-02