While not directly security related, I want to talk about how we relay information.
Many times people will latch on to a position, and right or wrong they will defend that position. I don’t really have a problem with that. What I have a problem with is when people take a position, espouse that position as fact, and then when asked to cite supporting information they tell people to go find it themselves.
This actually happened to me last week. I was a little shocked to hear that; you take a position, and when I ask you to cite a reference, any reference, you tell me to go find it myself. Now I see that as a cop out, a lack of conviction in the position taken.
Everything that I post on this blog is based on my own observation and analysis of the way I look at security and the facts that I am aware of. At the same time, I want to stay off the errata page at attrition.
I’m always open to changing my views when presented with other facts that I may not have been aware of. I take ownership of the content on this blog, if I make an assertion I will usually have facts to back it up, and if I don’t I will make sure that I state that my assertions are made with little to back them up. Should someone want to offer new information to anything that I post I welcome it.
I will generally approve all comments, even those that I disagree with. The only reason that I have comments wait for approval is the simple fact that I don’t need 30 comments about SEO. I’m quite comfortable with my obscurity.