<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The cost of phishing</title>
	<atom:link href="http://www.defendingthekingdom.com/archives/the-cost-of-phishing/feed" rel="self" type="application/rss+xml" />
	<link>http://www.defendingthekingdom.com/archives/the-cost-of-phishing</link>
	<description>Security and Privacy in Your Digital Life</description>
	<lastBuildDate>Fri, 03 Feb 2012 21:59:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Tom</title>
		<link>http://www.defendingthekingdom.com/archives/the-cost-of-phishing/comment-page-1#comment-4913</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Sun, 23 Mar 2008 19:12:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.defendingthekingdom.com/archives/the-cost-of-phishing#comment-4913</guid>
		<description>Yeah, I&#039;d definitely take the revealed preference of the pricing information over survey data.  The more I read, the more I have learned to completely disregard anything coming from surveys.

I don&#039;t have access to the written portion, but that sounds reasonable on Consumer Reports&#039; part.  I&#039;ve seen estimates on the cost of spam, but, as you suggest, those numbers rely on pretty subjective opinions and are not necessarily trusthworthy.</description>
		<content:encoded><![CDATA[<p>Yeah, I&#8217;d definitely take the revealed preference of the pricing information over survey data.  The more I read, the more I have learned to completely disregard anything coming from surveys.</p>
<p>I don&#8217;t have access to the written portion, but that sounds reasonable on Consumer Reports&#8217; part.  I&#8217;ve seen estimates on the cost of spam, but, as you suggest, those numbers rely on pretty subjective opinions and are not necessarily trusthworthy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Saxon</title>
		<link>http://www.defendingthekingdom.com/archives/the-cost-of-phishing/comment-page-1#comment-4912</link>
		<dc:creator>Ian Saxon</dc:creator>
		<pubDate>Sun, 23 Mar 2008 17:06:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.defendingthekingdom.com/archives/the-cost-of-phishing#comment-4912</guid>
		<description>From what I gathered in the written portion of their report, CR didn&#039;t think spam was costless - they recognized that there is a cost, but admitted they couldn&#039;t measure it.

Your point about the cost of maintaining a secure system is a good one. It is certainly expensive in terms of time, effort, and money. Each of us has to do our own calculation of the costs and benefits of these measures, &lt;a rel=&quot;nofollow&quot; href=&quot;http://www.defendingthekingdom.com/archives/security-is-not-a-switch&quot;&gt;something I&#039;ve written about before&lt;/a&gt;.

I have my own doubts about CR&#039;s numbers, but they run in the opposite direction. I wonder if individuals downplayed the costs of virus infection. For example, a 1 in 5 chance of losing $100 to a virus problem means people shouldn&#039;t spend more than $20 worth of money, time, and effort combating viruses. If that&#039;s true, those who spend $40 (the current price of Norton Anti-virus) on anti-virus software are making a big mistake, since they&#039;re spending double the expected cost of virus infection before they even install the software.

There is another explanation, however. When asked in a survey, perhaps individuals underreported the incidence or cost of virus troubles. But when they had to put their money where their mouth is, they declared that virus problems are at least as costly as $40. Add in the cost of the time and effort required for installation and maintenance, and we have a clue that individuals think viruses are considerably costlier than $40.</description>
		<content:encoded><![CDATA[<p>From what I gathered in the written portion of their report, CR didn&#8217;t think spam was costless &#8211; they recognized that there is a cost, but admitted they couldn&#8217;t measure it.</p>
<p>Your point about the cost of maintaining a secure system is a good one. It is certainly expensive in terms of time, effort, and money. Each of us has to do our own calculation of the costs and benefits of these measures, <a rel="nofollow" href="http://www.defendingthekingdom.com/archives/security-is-not-a-switch">something I&#8217;ve written about before</a>.</p>
<p>I have my own doubts about CR&#8217;s numbers, but they run in the opposite direction. I wonder if individuals downplayed the costs of virus infection. For example, a 1 in 5 chance of losing $100 to a virus problem means people shouldn&#8217;t spend more than $20 worth of money, time, and effort combating viruses. If that&#8217;s true, those who spend $40 (the current price of Norton Anti-virus) on anti-virus software are making a big mistake, since they&#8217;re spending double the expected cost of virus infection before they even install the software.</p>
<p>There is another explanation, however. When asked in a survey, perhaps individuals underreported the incidence or cost of virus troubles. But when they had to put their money where their mouth is, they declared that virus problems are at least as costly as $40. Add in the cost of the time and effort required for installation and maintenance, and we have a clue that individuals think viruses are considerably costlier than $40.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.defendingthekingdom.com/archives/the-cost-of-phishing/comment-page-1#comment-4911</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Sun, 23 Mar 2008 16:11:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.defendingthekingdom.com/archives/the-cost-of-phishing#comment-4911</guid>
		<description>Although I admittedly don&#039;t know Consumer Reports&#039; methodology, I kind of question their numbers.

For instance, they say that in terms of cost-per-incident, that spam doesn&#039;t have a cost (that cost-per-incident is non-applicable).  I would disagree.  There is a cost, an opportunity cost, in dealing with spam: lost wages and lost recreation time.  This cost quickly aggregates as you take into account the volume of spam most people deal with.  

Taking this a step further, for all 4 of the groups mentioned, preventative costs should be a fairly substantial chunk of their overall cost.  Economically rational agents should be willing to pay up to the marginal benefits of avoiding harm to avoid the cost of harm.  I mean, consider the aggregate amount spent developing spam filters, anti-virus programs, etc, then the time installing those programs, keeping them up-to-date, etc.  

I also wonder about whether people report the truth in these numbers.  Companies might underplay the costs of dealing with malware, whereas angry individuals might embellish the cost.</description>
		<content:encoded><![CDATA[<p>Although I admittedly don&#8217;t know Consumer Reports&#8217; methodology, I kind of question their numbers.</p>
<p>For instance, they say that in terms of cost-per-incident, that spam doesn&#8217;t have a cost (that cost-per-incident is non-applicable).  I would disagree.  There is a cost, an opportunity cost, in dealing with spam: lost wages and lost recreation time.  This cost quickly aggregates as you take into account the volume of spam most people deal with.  </p>
<p>Taking this a step further, for all 4 of the groups mentioned, preventative costs should be a fairly substantial chunk of their overall cost.  Economically rational agents should be willing to pay up to the marginal benefits of avoiding harm to avoid the cost of harm.  I mean, consider the aggregate amount spent developing spam filters, anti-virus programs, etc, then the time installing those programs, keeping them up-to-date, etc.  </p>
<p>I also wonder about whether people report the truth in these numbers.  Companies might underplay the costs of dealing with malware, whereas angry individuals might embellish the cost.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

