Mark Graff's Home Page

 

 

  • On practical security complications, at the CGSR "Beyond Moore's Law" Workshop, 9 Dec 99:

"I will spare you all of the sordid details, but believe me, trying to convince some vice president that he needs to take his critical system off line on a Sunday night so that I can apply security patches is a very difficult thing to do, so that (and I think it would apply very widely) the critical systems are the ones that have the oldest technology, have the lowest patch level, and this is another factor that is going to influence trying to secure cyberspace." Comments on Network Information Security

 

  • On hiring hackers, in various trade journal ads, spring 2001:

"The truth is, you have choices.

"The truth is, security engineering is a craft practiced by thousands of responsible engineers the world over. Bonded, certified, trained professionals. We’re not hard to find.

"The truth is, the best people to engage for this work are grownups. People who have invested their careers in the study of network security, who have dedicated their lives to building a safer Internet for the future.

"The truth is, the best way to prevent computer attacks is to foster a culture of respect for other people’s information, enterprises, and intellectual property. And that means not rewarding miscreants for breaking into other people’s computers by hiring them to help secure yours. Doesn’t it?"  Don't Hire Hackers