History has taught us: never underestimate the amount of money, time, and effort someone will expend to thwart a security system. It's always better to assume the worst. Assume your adversaries are better than they are. Assume science and technology will soon be able to do things they cannot yet. Give yourself a margin for error. Give yourself more security than you need today. When the unexpected happens, you'll be glad you did.
Amateurs hack systems, professionals hack people.
Interpretation
What this quote means
The quote emphasizes that while amateurs focus on technical skills, true experts understand and manipulate human behavior.
Bruce Schneier's quote highlights a critical distinction between amateurs and professionals in the field of hacking. Amateurs often concentrate on the technical aspects of systems, such as exploiting software vulnerabilities, whereas professionals recognize that understanding human psychology and social engineering is essential for successful hacking. This insight emphasizes that the most effective hacking often involves manipulating people rather than just breaking into computer systems.
Themes
In practice
Example use cases
This quote can be used in a cybersecurity training session to emphasize the importance of understanding the human factor in security.
More from Bruce Schneier
All quotes βThe whole notion of passwords is based on an oxymoron. The idea is to have a random string that is easy to remember. Unfortunately, if it's easy to remember, it's something nonrandom like 'Susan.' And if it's random, like 'r7U2*Qnp,' then it's not easy to remember.
This is not the internet the world needs, or the internet its creators envisioned. We need to take it back. And by we, I mean the engineering community.
It is poor civic hygiene to install technologies that could someday facilitate a police state.
You can't defend. You can't prevent. The only thing you can do is detect and respond.
Digital files cannot be made uncopyable, any more than water can be made not wet.
Similar quotes
YouTube has a hundred engineers who are trying to get the perfect next video to play automatically. And their techniques are only going to get more and more perfect over time, and we will have to resist the perfect.
Space tourism is a logical outgrowth of the adventure tourist market.
The one thing perhaps that technology hasn't always given us is a sense of how to make the wisest use of technology.
In many ways, I am very happy about the whole Linux commercial market because the commercial market is doing all these things that I have absolutely zero interest in doing myself.
There's no magic line between an application and an operating system that some bureaucrat in Washington should draw.
Once the Xerox copier was invented, diplomacy died.