<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Why User Education Will Never Work</title>
	<atom:link href="http://www.riskbloggers.com/kurtseifried/2006/11/draft-security-expert-user-education-is-pointless-agreed/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.riskbloggers.com/kurtseifried/2006/11/draft-security-expert-user-education-is-pointless-agreed/</link>
	<description>Security Wisdom Ahead of the Curve</description>
	<pubDate>Sun, 11 May 2008 23:43:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: LonerVamp</title>
		<link>http://www.riskbloggers.com/kurtseifried/2006/11/draft-security-expert-user-education-is-pointless-agreed/#comment-2789</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Mon, 19 Mar 2007 13:34:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.riskbloggers.com/2006/11/draft-security-expert-user-education-is-pointless-agreed/#comment-2789</guid>
		<description>That Dekalb example is a pretty extreme one, and ingenius at that. Even I would blink a few times and really investigate that link and email as opposed to knee-jerk delete.

But I hear your point and I do agree. User education alone won't save us any more than it has saved us against pretty much any other "security" "crime" in our country (teen pregnancy, drug use, etc). It helps, especially when people are receptive, but we can't assume everyone will be receptive.

At least with technology we have some absolutes, or as close as we can get to them.

Then again, we get down to how far can we take technology before users are no longer using computer systems but rather punchboards that do their 3 tasks and that's it?</description>
		<content:encoded><![CDATA[<p><!-- google_ad_section_start -->That Dekalb example is a pretty extreme one, and ingenius at that. Even I would blink a few times and really investigate that link and email as opposed to knee-jerk delete.</p>
<p>But I hear your point and I do agree. User education alone won&#8217;t save us any more than it has saved us against pretty much any other &#8220;security&#8221; &#8220;crime&#8221; in our country (teen pregnancy, drug use, etc). It helps, especially when people are receptive, but we can&#8217;t assume everyone will be receptive.</p>
<p>At least with technology we have some absolutes, or as close as we can get to them.</p>
<p>Then again, we get down to how far can we take technology before users are no longer using computer systems but rather punchboards that do their 3 tasks and that&#8217;s it?<!-- google_ad_section_end --></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ricst</title>
		<link>http://www.riskbloggers.com/kurtseifried/2006/11/draft-security-expert-user-education-is-pointless-agreed/#comment-15</link>
		<dc:creator>ricst</dc:creator>
		<pubDate>Fri, 10 Nov 2006 05:24:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.riskbloggers.com/2006/11/draft-security-expert-user-education-is-pointless-agreed/#comment-15</guid>
		<description>I guess education didn't work with the author of this article ;)

But it certainly does work whenever students/employees see a clear, personal benefit to learning the material, and the presentation is at a level they can understand.  Example: If you can train someone how to reduce the chance of their system getting hacked by malware, they can readily appreciate the benefit of not having to go a few days without their system while it's being repaired.  Everyone listens to WII-FM (What's in it for me?), and as long as security education addresses that question, almost everyone will at least pay attention, if not actually learn something useful.</description>
		<content:encoded><![CDATA[<p><!-- google_ad_section_start -->I guess education didn&#8217;t work with the author of this article ;)</p>
<p>But it certainly does work whenever students/employees see a clear, personal benefit to learning the material, and the presentation is at a level they can understand.  Example: If you can train someone how to reduce the chance of their system getting hacked by malware, they can readily appreciate the benefit of not having to go a few days without their system while it&#8217;s being repaired.  Everyone listens to WII-FM (What&#8217;s in it for me?), and as long as security education addresses that question, almost everyone will at least pay attention, if not actually learn something useful.<!-- google_ad_section_end --></p>
]]></content:encoded>
	</item>
</channel>
</rss>
