Although He's Wrong About The Probability In That Second Bit

Two of my favorite passages from Bruce Schneier's Secrets and Lies: Digital Security in a Networked World:

Several years ago Microsoft made a big deal about Windows NT getting a C2 security rating. They were much less forthcoming with the fact that this rating only applied if the computer was not attached to a network and had no network card, had its floppy drive epoxied shut, and was running on a Compaq 386.

Large gaping security holes are okay if the probability of attack is zero. (Tokyo is still vulnerable to attacks by giant fire-breathing lizards, for example.)

Where Am I?

This page contains a single entry from the blog posted on April 29, 2005.

The previous post in this blog was Travel Safety.

The next post in this blog is Shut Up Internet!.

Many more can be found in the archives, listed in the sidebar on the home page.

Subscribe