Re: The wheel reinvention mystery

"Arik Baratz" <[email protected]>
Newsgroups gmane.culture.hackers.israel
Message-ID <[email protected]>
On 9/21/06, Nadav Har'El <nyh-TS7m/[email protected]> wrote:

> In my previous post on the subject I gave a few real-world examples of
> people's awe and blind acceptance at the face of "security excuses".
> Your post is unfortunately another example - where you blindly accept
> from the "security" as a good excuse from the "first volunteer", for why we
> should accept the system he designed, even if it doesn't do what we need
> it to do.

I'd say that some of the time it's used as an excuse, some of the time
to create the allusion of security, and the rest of the time it's just
because most people don't really understand security.

An example for the first is airliners requiring an ID to board a
plane. The airliners want to prevent the ticket resale market so they
jumped on the Sept. 11th bandwagon and enforce security checks.

An example for the second is the TSA, which checks are so useless a
researcher managed to get all the components of a bomb aboard an
airplane and assemble it in 15 minutes in the toilets. Twice. They
just search for the wrong things. A few days after Sept. 11th I flew
back from the US to Israel. The guy was going through my luggage and I
asked him, what are you looking for? He told me that they just told
him to browse through people's bag, and he got zero instructions on
what to look for. It does look very elaborate, though.

And an example of the 3rd is the check in to buildings where you have
to sign your name. Absolutely no incentive for me to sign my real
name. Sometime they check your ID and then allow you to sign in...
yourself... and they don't verify that the name you signed in with is
the actual name on your ID.

Yet in the right context you can claim that X is more secure than Y.
There are many assumptions involved, and all in all, there are things
that, all else being equal, are more secure.

-- Arik


 
Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/hackers-il/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/hackers-il/join
    (Yahoo! ID required)

<*> To change settings via email:
    mailto:[email protected] 
    mailto:[email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.