2
Real-World Security
•It’s about risk, locks, and deterrence.
-Risk management: cost of security < expected loss
-Perfect security costs way too much
-Locks good enough that bad guys break in rarely
-Bad guys get caught and punished enough to be deterred, so police / courts must be good enough.
-Can recover from damage at an acceptable cost.
•Internet security similar, but
little accountability
–Can’t identify the bad guys, so can’t deter them
•