"[R]eal security is not something you build -- it's something you
get when you leave out all the other garbage as part of your design
process. Purpose-designed and purpose-built software is more expensive
to build, but cheaper to maintain. The prevailing wisdom about
software return on investment doesn't factor in patching and
patch-related downtime, because if it did, the numbers would stink.
Meanwhile, I've seen purpose-built Internet systems run for years
without patching because they didn't rely on bloated components. I
doubt industry will catch on." -- Marcus Ranum, in
"Security in Ten Years" (a conversation between Marcus Ranum
and Bruce Schneier )
[
thanks to
vvalkyri
for linking to it]
[To my friends celebrating Yom Kippur starting tonight, may you
have an easy fast -- Gmar Chatima Tovah!
And to
doubleplus,
happy birthday!]