Monday, August 21, 2006

Evidence Not Bias

This past week I saw 5 computers with identical symptoms. The root varied slightly. Just when I had it figured out, another root cause came up. Four were due to a downloader Trojan, the fifth was mechanical. It took me some time to figure out that the fifth was a mechanical issue and not an infection.

I am amazed at how I can let my own bias take minimal fact to get a conclusion where if I look for all the facts, I would get lead in another direction. I need to be continually aware of my own partiality. Personal human bias shades the facts to a conclusion that I want.

I see this same thing happening with computer security protection software vendors. The vendors rely on their reputation and little or no supporting evidence from independent labs. They are rated by magazine and trade journal tests. The very same publications are where the computer security vendors buy ad space.

Many of the less popular computer security software vendors have an A+ rating by independent labs. They don’t get the same level of attention. You rarely hear about these vendors in the press because they play it low key. They do not have security breaches, because they are doing their job. When the trade magazines review the less popular software it is usually below the more popular vendor products.

Bias and money does make the decisions. When it comes to computer security decisions should be made on logic and evidence. In the words a CSI, Gil Grisham, “Follow the evidence.”


2006
E.F. Cussins
This work is licensed under a
Creative Commons Attribution-ShareAlike 2.5 License
.

No comments: