This is a great blog posting: Security Absurdity: The Complete, Unquestionable, And Total Failure of Information Security. The data and links are comprehensive, and the message is right on. There is a tone of rant to the message, but it is justified.
I was thinking of writing something like this, but Noam has done it first, and maybe more completely in some areas than I would have. I probably would have also said something about the terrible state of Federal support for infosec research, however, and also mentioned the PITAC report on cyber security.
[posted with ecto]
Comments
The author has posted an update:
Community Comments & Feedback to Security Absurdity Article - the Good, the Bad and the Ugly.
http://www.securityabsurdity.com/comments.php