Quote:
The problem with low assurance security tools (Like ZA for example) is the fact that you don't know if they have failed to protect you, unless a successful attacker wishes to let you know.
I've always wondered about this... isn't that true for every single security application? I realize that if, for example, you have two antivirus solutions in place and one of them detects a virus that the other didn't, then you can say that the other solution failed... but if neither picks it up, how are you going to know that they failed to protect you? I think this problem falls in the "how do you know if your anti-flu shot worked? Just because you didn't get the flu?" category...