remain unchanged My chapters on cryptography and its limits, on authentication and authorization, and on threats, attacks, and adversaries could largely have been written yesterday (Go read my section in Chapter on “national intelligence organizations” as an adversary, and think about it in terms of what we know today about the NSA.) To me, the most important part of Secrets & Lies is in Chapter 24, where I talk about security as a combination of protection, detection, and response This might seem like a trivial observation, and even back then it was obvious if you looked around at security in the real world, but back in 2000 it was a bigger deal We were still very much in the mindset of security equals protection The goal was to prevent attacks: through cryptography, access control, firewalls, antivirus, and all sorts of other technologies The idea that you had to detect attacks was still in its infancy Intrusion Detection Systems (IDS) were just starting to become popular Fully fleshing out detection is what led me to the concept of continually monitoring your network against attack, and to start the company called Counterpane Internet Security, Inc Now there are all sorts of products and services that detect Internet attacks IDS has long been a robust product category There are log moniix fbetw.indd 2/18/15 7:04 