Showing posts with label logic. Show all posts
Showing posts with label logic. Show all posts

Tuesday, 16 June 2009

Good logic, bad logic

The world sadly to say is still full of poor logic and poorly argued decisions. ID Cards, NHS computers, the Millenium Dome etc. are excused with shoddy logic and opinions with little or no backup information. Sometimes some faux data is used to backup an argument when the weakness is more than obvious to the casual observer. For instance, a recent survey of Teaching Assistants said that a high percentage of them were expected to carry out tasks they were not trained for such as medical work. The number of respondents was 150 so already the data is weakly representative unless it can be considered a good representation of the population (usually achieved by including both genders across a large part of the country in different schools). However, did anyone else assume that the sort of people likely to fill in the forms are the sort of people who are concerned about something in which case the results are likely to show a high cause of concern.
Another thing I saw today was review of an encrypted USB stick that automatically encrypts everything you write to it in case it gets stolen. The reviewer concluded that because it was so expensive, for a fraction of the price, you could simply encrypt the data yourself and write it to a cheap stick instead. Sadly that is purely an economic argument. Hardware encryption is faster but the key to this argument is that the user does not have to do anything special or run any extra programs etc. If it is used, it is basically foolproof and that is the key to a secure product. You have a DIY job and guaranteed the one time that the user doesn't have time to encrypt the data is when it is lost or stolen and once the data is out, it is out, it cannot be retrieved from the public arena and re-hidden!
I wish people would think more about stuff, be objective and expect people to backup their arguments with good data, then we can concentrate on the parts of the decision which are subjective and not waste time on what should be a no-brainer.

Monday, 30 March 2009

More insanity in the made-up numbers department

I was just reading this about people claiming the amount of global cybercrime outstripped the international drug trade by $1T against $400Bn. As the reporter pointed out, do they expect us to believe that the global cybercrime trade is higher than Saudi Arabias annual domestic product of $555Bn from 2007. As if.
What particularly troubled me was the comment by security firm Finjan about justifying the touting of these numbers: "In our Q1 2009 report on cybercrime, for example, we revealed that one single rogueware network are raking in $10,800 a day, or $39.42 million a year," it said. "If you extrapolate those figures across the many thousands of cybercrime operations that exist on the Internet at any given time, the results easily reach a trillion dollars."
Can anyone else see the problem here? These people are supposed to be experts and not even their statistics make any sense. I am not a statistician or an economist but let us expose the error in their logic.
1) The example they used of a company taking in $11K per day would not have been making this every day for a year. They would more than likely either been tracked down and shut down or their source of revenue would have dried up as virus-checkers are updated or stolen credit card details are blocked.
2) This example of a company would be at the high end of cybercrime. Most people who write worms either don't make any money or certainly not as much as they might want and certainly not $11 per day. How many people would really make that much in a day amongst the 'many thousands of operations'? Not many!
So the evidence that was probably "company X made $11K in a day last year" becomes "every cybercrime company makes $11K every day of every year" it has been multiplied by 365 and then by thousands. To think these people probably get paid!!