> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100%…
If you wouldn't mind I'd really like to get your opinion on this proposed hardware solution I posted a while back: https://news.ycombinator.com/item?id=22343786
DMZ networks are hard to get right and hard to admin, and almost always end up getting some sort of exception for certain business needs.
Asking a user to admin that, or having no admin at all, feels almost impossible.