Bruce Schneier's comments on a security Underwriters Laboratory. As always, a well-thought-out commentary well worth reading. " Second, network security is much too hard to test. Again, safes are easy. Breaking into them requires skill but is reasonably straightforward. Modern software . . .
Bruce Schneier's comments on a security Underwriters Laboratory. As always, a well-thought-out commentary well worth reading. " Second, network security is much too hard to test. Again, safes are easy. Breaking into them requires skill but is reasonably straightforward. Modern software is obscenely complex: There's an enormous number of features, configurations, implementations. And then there are interactions between different products, different vendors, and different networks. In the past, I've written extensively about complexity and the impossibility of testing security. For now, suffice it to say that testing any reasonably sized software product would cost millions of dollars and wouldn't guarantee anything at the end. And worse, if you updated the product you'd have to test it all over again."

The link for this article located at ZDNet is no longer available.