|
From: Jeroen v. A. <kr...@at...> - 2008-10-01 23:26:08
|
Melvin wrote: > Just when I was sure I'd finally found the perfect place to put my > skills to use. :) Hah ;-) > I regularly explain the realities of the computer > world to my users, whatever their level of expertise. Well ideally one should not have to educate them. I'd say it's best to just state that that's the way it is and it can't be done otherwise or better, else it would already have happened. Check "#5) Educating Users" on http://www.ranum.com/security/computer_security/editorials/dumb/. "(...)The real question to ask is not "can we educate our users to be better at security?" it is "why do we need to educate our users at all?" In a sense, this is another special case of "Default Permit" - why are users getting executable attachments at all? Why are users expecting to get E-mails from banks where they don't have accounts? Most of the problems that are addressable through user education are self-correcting over time. As a younger generation of workers moves into the workforce, they will come pre-installed with a healthy skepticism about phishing and social engineering.(...)" Greetings, Jeroen |