Security quotes of the week
- How many people have at some point received signed email (S/MIME, PGP, whatever)?
- Of the above, how many people have been warned about some sort of validation failure in said signed email (expired cert, couldn't find the key, signature didn't validate, couldn't find gpg for the validation, etc)?
- Of the above again, how many people immediately deleted the email without looking at it (it could be a drive-by download/infection)?
I would guess that by the time you've got to the third question, you'd be down to zero people (I've been waiting for an excuse to do this poll in a roomful of people at a security conference, just need to get the right talk to ask it at).
