Wednesday, April 23, 2008

The Six Dumbest Ideas in Computer Security

Well, it's been a while since I had an opportunity to post. The last couple of months have been very busy. Anyway, I stumbled across this link today (thanks to my brother):

The Six Dumbest Ideas in Computer Security, by Macrus Ranum

It's not new (Sept 2005), but it's really good on a number of dimensions. First up, it's spot on topic. The computer security industry seems to get bigger ever year (on both sides of the legal fence), but it still manages to congratulate itself over and over again about how things are going so well. But I also really like the way that Marcus gives very useful names to the "anti-good ideas" he discusses. Phenomenology is always (is it?) the first step in breaking down complex problems.

M@