 That whole blurb was fairly well said, wasn't sure where you were going in the first few sentences, but I like what you have to say about the industry and it's middle and upper leadership. It's a scary world to live in right now.


The only issue with this is that many times it is the same PHBs asking
these sorts of questions.  I've been hearing vendors tell me about
things being encrypted for ages, and usually somebody just XORed
something before storing it in the database.

Even decent encryption is only as good as its implementation, and I
doubt that many companies seriously check to see that the encryption
even tries to be decent.

I think the insurance industry actually has the potential to change
things here.  At work the fire insurance auditor always seems to be
the driver for making sure those breaker boxes are clear and so on.
Insurance companies are actually in the business of risk estimation
and if they get it wrong it hits their bottom line.  On the other
hand, many big companies just self-insure for these sorts of things
and fire a scapegoat when things go wrong even though they never had
enough budget to do anything to prevent the problem in the first

