Q&A with Bruce Schneier

Expert says security benefits must be weighed against tradeoffs

  • Jonathan Gaw
  • Minneapolis Star Tribune
  • February 23, 2008

Q: When a company or government entity has a security proposal, how should they evaluate that? What sort of principles should they be looking for to determine whether this is going to be an effective security solution?

A: First, you have to understand that security is a tradeoff. Whether you give money, or time, or convenience, or civil liberties, or American servicemen’s lives, you give something and you get some security in return. There’s no such thing as absolute security: It’s a continuum and it’s a tradeoff.

The next question to ask is, is it worth it? You have to go through a security tradeoff, tease out what the risks are, how good the countermeasures are, what the costs are, and then decide “Is it worth it?”…

Sidebar photo of Bruce Schneier by Joe MacInnis.