Earlier quoted context omitted.
I'm sorry, but I think this is making the same errors in the opposite direction. 1) Yes, child abduction/predation is unlikely ... because we've adopted a huge number of countermeasures that close of this vector. That doesn't (by itself) mean you can just stop doing those measures and act like the risk is still low. 2) The risk of death by bathtub is not 75%. 3) Terrorists ramp up efforts against any vector they've f…
> Yes, child abduction/predation is unlikely ... because we've adopted a huge number of countermeasures that close of this vector. Actually, most of the social "countermeasures" were adopted after high-profile single incidents in the 1990s (perhaps largely because the larger 1960s-1980s crime wave that had been the pretext for expanding government powers in the law enforcement arena previously was ending, and a new p…
Say someone cracks a major bank account by guessing "password" as the password. The bank changes the password.
I claim that the weak password was a security risk, and changing it was the right response.
Someone comes a long and gives me a data-intense lecture about "well, electronic bank theft was already declining, and it accounts for only a tiny fraction of financial losses, so changing the password was a waste of time, and was in the context of the IT department using a bunch of pretexts to order people around".
How would you refute that, given all the evidence on their side?