Top Ten Ways to Stir the Cyber Pot
I spent a few minutes just now thinking about the digital security issues that people periodically raise on their blogs, or on Twitter, or at conferences. We constantly argue about some of these topics. I don't think we'll ever resolve any of them.
If you want to start a debate/argument/flamewar in security, pick any of the following.
- "Full disclosure" vs "responsible disclosure" vs whatever else
- Threat intelligence sharing
- Value of security certifications
- Exploit sales
- Advanced-ness, Persistence-ness, Threat-ness, Chinese-ness of APT
- Reality of "cyberwar"
- "Builders vs Breakers"
- "Security is an engineering problem," i.e., "building a new Internet is the answer."
- "Return on security investment"
- Security by mandate or legislation or regulation
Did I miss any subjects people raise to "stir the cyber pot?"