[Script Info] Title: [Events] Format: Layer, Start, End, Style, Name, MarginL, MarginR, MarginV, Effect, Text Dialogue: 0,0:00:00.75,0:00:03.03,Default,,0000,0000,0000,,So, security is two different things: Dialogue: 0,0:00:03.05,0:00:05.58,Default,,0000,0000,0000,,it's a feeling, and it's a reality. Dialogue: 0,0:00:05.60,0:00:07.02,Default,,0000,0000,0000,,And they're different. Dialogue: 0,0:00:07.05,0:00:10.48,Default,,0000,0000,0000,,You could feel secure even if you're not. Dialogue: 0,0:00:10.50,0:00:12.48,Default,,0000,0000,0000,,And you can be secure Dialogue: 0,0:00:12.50,0:00:14.35,Default,,0000,0000,0000,,even if you don't feel it. Dialogue: 0,0:00:14.37,0:00:16.49,Default,,0000,0000,0000,,Really, we have two separate concepts Dialogue: 0,0:00:16.52,0:00:18.17,Default,,0000,0000,0000,,mapped onto the same word. Dialogue: 0,0:00:18.70,0:00:22.33,Default,,0000,0000,0000,,And what I want to do in this talk\Nis to split them apart -- Dialogue: 0,0:00:22.35,0:00:25.96,Default,,0000,0000,0000,,figuring out when they diverge\Nand how they converge. Dialogue: 0,0:00:26.45,0:00:28.73,Default,,0000,0000,0000,,And language is actually a problem here. Dialogue: 0,0:00:28.75,0:00:30.83,Default,,0000,0000,0000,,There aren't a lot of good words Dialogue: 0,0:00:30.85,0:00:32.91,Default,,0000,0000,0000,,for the concepts\Nwe're going to talk about. Dialogue: 0,0:00:34.04,0:00:38.16,Default,,0000,0000,0000,,So if you look at security\Nfrom economic terms, Dialogue: 0,0:00:38.18,0:00:39.83,Default,,0000,0000,0000,,it's a trade-off. Dialogue: 0,0:00:39.85,0:00:43.98,Default,,0000,0000,0000,,Every time you get some security,\Nyou're always trading off something. Dialogue: 0,0:00:44.01,0:00:45.85,Default,,0000,0000,0000,,Whether this is a personal decision -- Dialogue: 0,0:00:45.88,0:00:48.89,Default,,0000,0000,0000,,whether you're going to install\Na burglar alarm in your home -- Dialogue: 0,0:00:48.91,0:00:50.07,Default,,0000,0000,0000,,or a national decision, Dialogue: 0,0:00:50.09,0:00:52.40,Default,,0000,0000,0000,,where you're going to invade\Na foreign country -- Dialogue: 0,0:00:52.43,0:00:56.21,Default,,0000,0000,0000,,you're going to trade off something:\Nmoney or time, convenience, capabilities, Dialogue: 0,0:00:56.23,0:00:58.23,Default,,0000,0000,0000,,maybe fundamental liberties. Dialogue: 0,0:00:58.26,0:01:01.53,Default,,0000,0000,0000,,And the question to ask\Nwhen you look at a security anything Dialogue: 0,0:01:01.56,0:01:04.94,Default,,0000,0000,0000,,is not whether this makes us safer, Dialogue: 0,0:01:04.96,0:01:07.18,Default,,0000,0000,0000,,but whether it's worth the trade-off. Dialogue: 0,0:01:07.20,0:01:10.43,Default,,0000,0000,0000,,You've heard in the past\Nseveral years, the world is safer Dialogue: 0,0:01:10.45,0:01:12.34,Default,,0000,0000,0000,,because Saddam Hussein is not in power. Dialogue: 0,0:01:12.37,0:01:14.97,Default,,0000,0000,0000,,That might be true,\Nbut it's not terribly relevant. Dialogue: 0,0:01:14.100,0:01:17.83,Default,,0000,0000,0000,,The question is: Was it worth it? Dialogue: 0,0:01:17.85,0:01:20.31,Default,,0000,0000,0000,,And you can make your own decision, Dialogue: 0,0:01:20.33,0:01:23.07,Default,,0000,0000,0000,,and then you'll decide\Nwhether the invasion was worth it. Dialogue: 0,0:01:23.09,0:01:26.65,Default,,0000,0000,0000,,That's how you think about security:\Nin terms of the trade-off. Dialogue: 0,0:01:26.68,0:01:29.28,Default,,0000,0000,0000,,Now, there's often no right or wrong here. Dialogue: 0,0:01:29.95,0:01:33.26,Default,,0000,0000,0000,,Some of us have a burglar alarm\Nsystem at home and some of us don't. Dialogue: 0,0:01:33.28,0:01:36.01,Default,,0000,0000,0000,,And it'll depend on where we live, Dialogue: 0,0:01:36.04,0:01:37.96,Default,,0000,0000,0000,,whether we live alone or have a family, Dialogue: 0,0:01:37.98,0:01:39.65,Default,,0000,0000,0000,,how much cool stuff we have, Dialogue: 0,0:01:39.68,0:01:42.84,Default,,0000,0000,0000,,how much we're willing\Nto accept the risk of theft. Dialogue: 0,0:01:43.68,0:01:46.63,Default,,0000,0000,0000,,In politics also,\Nthere are different opinions. Dialogue: 0,0:01:47.20,0:01:51.63,Default,,0000,0000,0000,,A lot of times, these trade-offs\Nare about more than just security, Dialogue: 0,0:01:51.66,0:01:53.52,Default,,0000,0000,0000,,and I think that's really important. Dialogue: 0,0:01:53.55,0:01:56.86,Default,,0000,0000,0000,,Now, people have a natural intuition\Nabout these trade-offs. Dialogue: 0,0:01:57.33,0:01:58.88,Default,,0000,0000,0000,,We make them every day. Dialogue: 0,0:01:59.55,0:02:03.08,Default,,0000,0000,0000,,Last night in my hotel room,\Nwhen I decided to double-lock the door, Dialogue: 0,0:02:03.10,0:02:05.10,Default,,0000,0000,0000,,or you in your car when you drove here; Dialogue: 0,0:02:05.93,0:02:07.41,Default,,0000,0000,0000,,when we go eat lunch Dialogue: 0,0:02:07.43,0:02:10.04,Default,,0000,0000,0000,,and decide the food's not\Npoison and we'll eat it. Dialogue: 0,0:02:10.06,0:02:13.23,Default,,0000,0000,0000,,We make these trade-offs again and again, Dialogue: 0,0:02:13.25,0:02:14.83,Default,,0000,0000,0000,,multiple times a day. Dialogue: 0,0:02:14.85,0:02:16.44,Default,,0000,0000,0000,,We often won't even notice them. Dialogue: 0,0:02:16.46,0:02:19.09,Default,,0000,0000,0000,,They're just part\Nof being alive; we all do it. Dialogue: 0,0:02:19.11,0:02:20.67,Default,,0000,0000,0000,,Every species does it. Dialogue: 0,0:02:21.21,0:02:24.08,Default,,0000,0000,0000,,Imagine a rabbit in a field, eating grass. Dialogue: 0,0:02:24.10,0:02:26.04,Default,,0000,0000,0000,,And the rabbit sees a fox. Dialogue: 0,0:02:26.60,0:02:28.64,Default,,0000,0000,0000,,That rabbit will make\Na security trade-off: Dialogue: 0,0:02:28.67,0:02:30.57,Default,,0000,0000,0000,,"Should I stay, or should I flee?" Dialogue: 0,0:02:31.12,0:02:32.74,Default,,0000,0000,0000,,And if you think about it, Dialogue: 0,0:02:32.76,0:02:35.32,Default,,0000,0000,0000,,the rabbits that are good\Nat making that trade-off Dialogue: 0,0:02:35.34,0:02:37.32,Default,,0000,0000,0000,,will tend to live and reproduce, Dialogue: 0,0:02:37.34,0:02:39.65,Default,,0000,0000,0000,,and the rabbits that are bad at it Dialogue: 0,0:02:39.68,0:02:41.15,Default,,0000,0000,0000,,will get eaten or starve. Dialogue: 0,0:02:41.70,0:02:43.31,Default,,0000,0000,0000,,So you'd think Dialogue: 0,0:02:44.31,0:02:48.62,Default,,0000,0000,0000,,that us, as a successful species\Non the planet -- you, me, everybody -- Dialogue: 0,0:02:48.65,0:02:51.22,Default,,0000,0000,0000,,would be really good\Nat making these trade-offs. Dialogue: 0,0:02:51.87,0:02:54.97,Default,,0000,0000,0000,,Yet it seems, again and again,\Nthat we're hopelessly bad at it. Dialogue: 0,0:02:56.51,0:02:59.31,Default,,0000,0000,0000,,And I think that's a fundamentally\Ninteresting question. Dialogue: 0,0:02:59.33,0:03:01.21,Default,,0000,0000,0000,,I'll give you the short answer. Dialogue: 0,0:03:01.23,0:03:03.88,Default,,0000,0000,0000,,The answer is, we respond\Nto the feeling of security Dialogue: 0,0:03:03.91,0:03:05.42,Default,,0000,0000,0000,,and not the reality. Dialogue: 0,0:03:06.60,0:03:09.30,Default,,0000,0000,0000,,Now, most of the time, that works. Dialogue: 0,0:03:10.28,0:03:11.78,Default,,0000,0000,0000,,Most of the time, Dialogue: 0,0:03:11.80,0:03:13.94,Default,,0000,0000,0000,,feeling and reality are the same. Dialogue: 0,0:03:15.52,0:03:19.03,Default,,0000,0000,0000,,Certainly that's true\Nfor most of human prehistory. Dialogue: 0,0:03:20.37,0:03:23.08,Default,,0000,0000,0000,,We've developed this ability Dialogue: 0,0:03:23.10,0:03:25.69,Default,,0000,0000,0000,,because it makes evolutionary sense. Dialogue: 0,0:03:26.72,0:03:29.100,Default,,0000,0000,0000,,One way to think of it\Nis that we're highly optimized Dialogue: 0,0:03:30.02,0:03:31.83,Default,,0000,0000,0000,,for risk decisions Dialogue: 0,0:03:31.85,0:03:34.39,Default,,0000,0000,0000,,that are endemic to living\Nin small family groups Dialogue: 0,0:03:34.42,0:03:36.95,Default,,0000,0000,0000,,in the East African Highlands\Nin 100,000 BC. Dialogue: 0,0:03:37.53,0:03:40.19,Default,,0000,0000,0000,,2010 New York, not so much. Dialogue: 0,0:03:41.62,0:03:44.82,Default,,0000,0000,0000,,Now, there are several biases\Nin risk perception. Dialogue: 0,0:03:44.85,0:03:46.59,Default,,0000,0000,0000,,A lot of good experiments in this. Dialogue: 0,0:03:46.61,0:03:50.22,Default,,0000,0000,0000,,And you can see certain biases\Nthat come up again and again. Dialogue: 0,0:03:50.24,0:03:51.59,Default,,0000,0000,0000,,I'll give you four. Dialogue: 0,0:03:51.62,0:03:54.83,Default,,0000,0000,0000,,We tend to exaggerate\Nspectacular and rare risks Dialogue: 0,0:03:54.85,0:03:56.83,Default,,0000,0000,0000,,and downplay common risks -- Dialogue: 0,0:03:56.85,0:03:58.37,Default,,0000,0000,0000,,so, flying versus driving. Dialogue: 0,0:03:59.19,0:04:02.98,Default,,0000,0000,0000,,The unknown is perceived\Nto be riskier than the familiar. Dialogue: 0,0:04:06.21,0:04:07.65,Default,,0000,0000,0000,,One example would be: Dialogue: 0,0:04:07.67,0:04:10.29,Default,,0000,0000,0000,,people fear kidnapping by strangers, Dialogue: 0,0:04:10.31,0:04:13.95,Default,,0000,0000,0000,,when the data supports that kidnapping\Nby relatives is much more common. Dialogue: 0,0:04:13.97,0:04:15.54,Default,,0000,0000,0000,,This is for children. Dialogue: 0,0:04:15.57,0:04:19.61,Default,,0000,0000,0000,,Third, personified risks\Nare perceived to be greater Dialogue: 0,0:04:19.63,0:04:21.14,Default,,0000,0000,0000,,than anonymous risks. Dialogue: 0,0:04:21.16,0:04:23.95,Default,,0000,0000,0000,,So, Bin Laden is scarier\Nbecause he has a name. Dialogue: 0,0:04:24.92,0:04:26.28,Default,,0000,0000,0000,,And the fourth is: Dialogue: 0,0:04:26.31,0:04:31.06,Default,,0000,0000,0000,,people underestimate risks\Nin situations they do control Dialogue: 0,0:04:31.09,0:04:34.05,Default,,0000,0000,0000,,and overestimate them\Nin situations they don't control. Dialogue: 0,0:04:34.08,0:04:37.46,Default,,0000,0000,0000,,So once you take up skydiving or smoking, Dialogue: 0,0:04:37.48,0:04:39.11,Default,,0000,0000,0000,,you downplay the risks. Dialogue: 0,0:04:39.78,0:04:42.83,Default,,0000,0000,0000,,If a risk is thrust upon you --\Nterrorism is a good example -- Dialogue: 0,0:04:42.85,0:04:44.01,Default,,0000,0000,0000,,you'll overplay it, Dialogue: 0,0:04:44.04,0:04:46.37,Default,,0000,0000,0000,,because you don't feel\Nlike it's in your control. Dialogue: 0,0:04:46.90,0:04:50.39,Default,,0000,0000,0000,,There are a bunch\Nof other of these cognitive biases, Dialogue: 0,0:04:50.41,0:04:52.75,Default,,0000,0000,0000,,that affect our risk decisions. Dialogue: 0,0:04:53.57,0:04:55.83,Default,,0000,0000,0000,,There's the availability heuristic, Dialogue: 0,0:04:55.85,0:05:00.03,Default,,0000,0000,0000,,which basically means we estimate\Nthe probability of something Dialogue: 0,0:05:00.05,0:05:03.39,Default,,0000,0000,0000,,by how easy it is to bring\Ninstances of it to mind. Dialogue: 0,0:05:04.57,0:05:06.35,Default,,0000,0000,0000,,So you can imagine how that works. Dialogue: 0,0:05:06.37,0:05:10.00,Default,,0000,0000,0000,,If you hear a lot about tiger attacks,\Nthere must be a lot of tigers around. Dialogue: 0,0:05:10.02,0:05:13.37,Default,,0000,0000,0000,,You don't hear about lion attacks,\Nthere aren't a lot of lions around. Dialogue: 0,0:05:13.39,0:05:15.69,Default,,0000,0000,0000,,This works, until you invent newspapers, Dialogue: 0,0:05:15.71,0:05:20.12,Default,,0000,0000,0000,,because what newspapers do\Nis repeat again and again Dialogue: 0,0:05:20.14,0:05:21.55,Default,,0000,0000,0000,,rare risks. Dialogue: 0,0:05:21.57,0:05:24.44,Default,,0000,0000,0000,,I tell people: if it's in the news,\Ndon't worry about it, Dialogue: 0,0:05:24.46,0:05:28.74,Default,,0000,0000,0000,,because by definition, news is something\Nthat almost never happens. Dialogue: 0,0:05:28.76,0:05:30.53,Default,,0000,0000,0000,,(Laughter) Dialogue: 0,0:05:30.55,0:05:33.48,Default,,0000,0000,0000,,When something is so common,\Nit's no longer news. Dialogue: 0,0:05:33.50,0:05:35.70,Default,,0000,0000,0000,,Car crashes, domestic violence -- Dialogue: 0,0:05:35.72,0:05:37.71,Default,,0000,0000,0000,,those are the risks you worry about. Dialogue: 0,0:05:38.45,0:05:40.60,Default,,0000,0000,0000,,We're also a species of storytellers. Dialogue: 0,0:05:40.62,0:05:42.74,Default,,0000,0000,0000,,We respond to stories more than data. Dialogue: 0,0:05:43.25,0:05:45.66,Default,,0000,0000,0000,,And there's some basic\Ninnumeracy going on. Dialogue: 0,0:05:45.68,0:05:48.83,Default,,0000,0000,0000,,I mean, the joke "One, two,\Nthree, many" is kind of right. Dialogue: 0,0:05:48.85,0:05:51.17,Default,,0000,0000,0000,,We're really good at small numbers. Dialogue: 0,0:05:51.20,0:05:53.53,Default,,0000,0000,0000,,One mango, two mangoes, three mangoes, Dialogue: 0,0:05:53.56,0:05:55.53,Default,,0000,0000,0000,,10,000 mangoes, 100,000 mangoes -- Dialogue: 0,0:05:55.56,0:05:58.53,Default,,0000,0000,0000,,it's still more mangoes\Nyou can eat before they rot. Dialogue: 0,0:05:58.56,0:06:01.83,Default,,0000,0000,0000,,So one half, one quarter,\None fifth -- we're good at that. Dialogue: 0,0:06:01.85,0:06:03.83,Default,,0000,0000,0000,,One in a million, one in a billion -- Dialogue: 0,0:06:03.85,0:06:05.42,Default,,0000,0000,0000,,they're both almost never. Dialogue: 0,0:06:06.29,0:06:09.70,Default,,0000,0000,0000,,So we have trouble with the risks\Nthat aren't very common. Dialogue: 0,0:06:10.50,0:06:12.48,Default,,0000,0000,0000,,And what these cognitive biases do Dialogue: 0,0:06:12.50,0:06:15.48,Default,,0000,0000,0000,,is they act as filters\Nbetween us and reality. Dialogue: 0,0:06:16.02,0:06:19.90,Default,,0000,0000,0000,,And the result is that feeling\Nand reality get out of whack, Dialogue: 0,0:06:19.92,0:06:21.30,Default,,0000,0000,0000,,they get different. Dialogue: 0,0:06:22.11,0:06:26.04,Default,,0000,0000,0000,,Now, you either have a feeling --\Nyou feel more secure than you are, Dialogue: 0,0:06:26.06,0:06:27.75,Default,,0000,0000,0000,,there's a false sense of security. Dialogue: 0,0:06:27.77,0:06:31.15,Default,,0000,0000,0000,,Or the other way, and that's a false\Nsense of insecurity. Dialogue: 0,0:06:31.76,0:06:34.64,Default,,0000,0000,0000,,I write a lot about "security theater," Dialogue: 0,0:06:34.66,0:06:37.34,Default,,0000,0000,0000,,which are products\Nthat make people feel secure, Dialogue: 0,0:06:37.36,0:06:39.34,Default,,0000,0000,0000,,but don't actually do anything. Dialogue: 0,0:06:39.36,0:06:41.92,Default,,0000,0000,0000,,There's no real word for stuff\Nthat makes us secure, Dialogue: 0,0:06:41.94,0:06:43.83,Default,,0000,0000,0000,,but doesn't make us feel secure. Dialogue: 0,0:06:43.85,0:06:46.57,Default,,0000,0000,0000,,Maybe it's what the CIA\Nis supposed to do for us. Dialogue: 0,0:06:48.28,0:06:50.45,Default,,0000,0000,0000,,So back to economics. Dialogue: 0,0:06:50.47,0:06:54.13,Default,,0000,0000,0000,,If economics, if the market,\Ndrives security, Dialogue: 0,0:06:54.15,0:06:58.100,Default,,0000,0000,0000,,and if people make trade-offs\Nbased on the feeling of security, Dialogue: 0,0:06:59.02,0:07:03.70,Default,,0000,0000,0000,,then the smart thing for companies to do\Nfor the economic incentives Dialogue: 0,0:07:03.73,0:07:05.78,Default,,0000,0000,0000,,is to make people feel secure. Dialogue: 0,0:07:06.68,0:07:09.01,Default,,0000,0000,0000,,And there are two ways to do this. Dialogue: 0,0:07:09.04,0:07:11.83,Default,,0000,0000,0000,,One, you can make people actually secure Dialogue: 0,0:07:11.85,0:07:13.31,Default,,0000,0000,0000,,and hope they notice. Dialogue: 0,0:07:13.34,0:07:16.18,Default,,0000,0000,0000,,Or two, you can make people\Njust feel secure Dialogue: 0,0:07:16.20,0:07:18.08,Default,,0000,0000,0000,,and hope they don't notice. Dialogue: 0,0:07:19.14,0:07:20.52,Default,,0000,0000,0000,,Right? Dialogue: 0,0:07:20.54,0:07:23.68,Default,,0000,0000,0000,,So what makes people notice? Dialogue: 0,0:07:24.24,0:07:25.62,Default,,0000,0000,0000,,Well, a couple of things: Dialogue: 0,0:07:25.65,0:07:27.91,Default,,0000,0000,0000,,understanding of the security, Dialogue: 0,0:07:27.94,0:07:29.83,Default,,0000,0000,0000,,of the risks, the threats, Dialogue: 0,0:07:29.85,0:07:31.72,Default,,0000,0000,0000,,the countermeasures, how they work. Dialogue: 0,0:07:31.75,0:07:34.04,Default,,0000,0000,0000,,But if you know stuff, you're more likely Dialogue: 0,0:07:34.90,0:07:37.12,Default,,0000,0000,0000,,to have your feelings match reality. Dialogue: 0,0:07:37.85,0:07:40.100,Default,,0000,0000,0000,,Enough real-world examples helps. Dialogue: 0,0:07:41.02,0:07:43.58,Default,,0000,0000,0000,,We all know the crime rate\Nin our neighborhood, Dialogue: 0,0:07:43.60,0:07:46.40,Default,,0000,0000,0000,,because we live there,\Nand we get a feeling about it Dialogue: 0,0:07:46.43,0:07:48.30,Default,,0000,0000,0000,,that basically matches reality. Dialogue: 0,0:07:49.78,0:07:51.98,Default,,0000,0000,0000,,Security theater is exposed Dialogue: 0,0:07:52.01,0:07:54.80,Default,,0000,0000,0000,,when it's obvious\Nthat it's not working properly. Dialogue: 0,0:07:55.95,0:07:58.62,Default,,0000,0000,0000,,OK. So what makes people not notice? Dialogue: 0,0:07:59.18,0:08:00.68,Default,,0000,0000,0000,,Well, a poor understanding. Dialogue: 0,0:08:01.38,0:08:04.53,Default,,0000,0000,0000,,If you don't understand the risks,\Nyou don't understand the costs, Dialogue: 0,0:08:04.55,0:08:06.71,Default,,0000,0000,0000,,you're likely to get the trade-off wrong, Dialogue: 0,0:08:06.73,0:08:09.22,Default,,0000,0000,0000,,and your feeling doesn't match reality. Dialogue: 0,0:08:09.24,0:08:10.98,Default,,0000,0000,0000,,Not enough examples. Dialogue: 0,0:08:11.62,0:08:15.12,Default,,0000,0000,0000,,There's an inherent problem\Nwith low-probability events. Dialogue: 0,0:08:15.66,0:08:19.47,Default,,0000,0000,0000,,If, for example, terrorism\Nalmost never happens, Dialogue: 0,0:08:19.50,0:08:24.10,Default,,0000,0000,0000,,it's really hard to judge the efficacy\Nof counter-terrorist measures. Dialogue: 0,0:08:25.26,0:08:28.83,Default,,0000,0000,0000,,This is why you keep sacrificing virgins, Dialogue: 0,0:08:28.85,0:08:31.52,Default,,0000,0000,0000,,and why your unicorn defenses\Nare working just great. Dialogue: 0,0:08:31.55,0:08:34.11,Default,,0000,0000,0000,,There aren't enough examples of failures. Dialogue: 0,0:08:35.85,0:08:38.64,Default,,0000,0000,0000,,Also, feelings that cloud the issues -- Dialogue: 0,0:08:38.66,0:08:42.69,Default,,0000,0000,0000,,the cognitive biases I talked\Nabout earlier: fears, folk beliefs -- Dialogue: 0,0:08:43.47,0:08:46.21,Default,,0000,0000,0000,,basically, an inadequate model of reality. Dialogue: 0,0:08:48.14,0:08:50.31,Default,,0000,0000,0000,,So let me complicate things. Dialogue: 0,0:08:50.34,0:08:52.32,Default,,0000,0000,0000,,I have feeling and reality. Dialogue: 0,0:08:52.34,0:08:55.14,Default,,0000,0000,0000,,I want to add a third element.\NI want to add "model." Dialogue: 0,0:08:55.58,0:08:57.93,Default,,0000,0000,0000,,Feeling and model are in our head, Dialogue: 0,0:08:57.95,0:09:01.40,Default,,0000,0000,0000,,reality is the outside world;\Nit doesn't change, it's real. Dialogue: 0,0:09:02.54,0:09:04.75,Default,,0000,0000,0000,,Feeling is based on our intuition, Dialogue: 0,0:09:04.78,0:09:06.40,Default,,0000,0000,0000,,model is based on reason. Dialogue: 0,0:09:07.12,0:09:09.16,Default,,0000,0000,0000,,That's basically the difference. Dialogue: 0,0:09:09.19,0:09:11.16,Default,,0000,0000,0000,,In a primitive and simple world, Dialogue: 0,0:09:11.19,0:09:13.32,Default,,0000,0000,0000,,there's really no reason for a model, Dialogue: 0,0:09:14.99,0:09:17.29,Default,,0000,0000,0000,,because feeling is close to reality. Dialogue: 0,0:09:17.31,0:09:18.68,Default,,0000,0000,0000,,You don't need a model. Dialogue: 0,0:09:19.34,0:09:21.49,Default,,0000,0000,0000,,But in a modern and complex world, Dialogue: 0,0:09:22.30,0:09:25.95,Default,,0000,0000,0000,,you need models to understand\Na lot of the risks we face. Dialogue: 0,0:09:27.10,0:09:29.39,Default,,0000,0000,0000,,There's no feeling about germs. Dialogue: 0,0:09:29.85,0:09:31.97,Default,,0000,0000,0000,,You need a model to understand them. Dialogue: 0,0:09:32.90,0:09:36.58,Default,,0000,0000,0000,,This model is an intelligent\Nrepresentation of reality. Dialogue: 0,0:09:37.15,0:09:41.90,Default,,0000,0000,0000,,It's, of course, limited\Nby science, by technology. Dialogue: 0,0:09:42.99,0:09:45.32,Default,,0000,0000,0000,,We couldn't have a germ theory of disease Dialogue: 0,0:09:45.34,0:09:47.87,Default,,0000,0000,0000,,before we invented\Nthe microscope to see them. Dialogue: 0,0:09:49.06,0:09:51.70,Default,,0000,0000,0000,,It's limited by our cognitive biases. Dialogue: 0,0:09:52.85,0:09:55.84,Default,,0000,0000,0000,,But it has the ability\Nto override our feelings. Dialogue: 0,0:09:56.25,0:09:59.35,Default,,0000,0000,0000,,Where do we get these models?\NWe get them from others. Dialogue: 0,0:09:59.38,0:10:04.59,Default,,0000,0000,0000,,We get them from religion,\Nfrom culture, teachers, elders. Dialogue: 0,0:10:05.04,0:10:08.46,Default,,0000,0000,0000,,A couple years ago,\NI was in South Africa on safari. Dialogue: 0,0:10:08.49,0:10:11.25,Default,,0000,0000,0000,,The tracker I was with grew up\Nin Kruger National Park. Dialogue: 0,0:10:11.27,0:10:14.03,Default,,0000,0000,0000,,He had some very complex\Nmodels of how to survive. Dialogue: 0,0:10:14.54,0:10:18.45,Default,,0000,0000,0000,,And it depended on if you were attacked\Nby a lion, leopard, rhino, or elephant -- Dialogue: 0,0:10:18.48,0:10:21.21,Default,,0000,0000,0000,,and when you had to run away,\Nwhen you couldn't run away, Dialogue: 0,0:10:21.24,0:10:24.32,Default,,0000,0000,0000,,when you had to climb a tree,\Nwhen you could never climb a tree. Dialogue: 0,0:10:24.34,0:10:25.69,Default,,0000,0000,0000,,I would have died in a day. Dialogue: 0,0:10:26.90,0:10:30.68,Default,,0000,0000,0000,,But he was born there,\Nand he understood how to survive. Dialogue: 0,0:10:31.23,0:10:32.83,Default,,0000,0000,0000,,I was born in New York City. Dialogue: 0,0:10:32.85,0:10:36.10,Default,,0000,0000,0000,,I could have taken him to New York,\Nand he would have died in a day. Dialogue: 0,0:10:36.12,0:10:37.13,Default,,0000,0000,0000,,(Laughter) Dialogue: 0,0:10:37.15,0:10:41.29,Default,,0000,0000,0000,,Because we had different models\Nbased on our different experiences. Dialogue: 0,0:10:43.03,0:10:45.50,Default,,0000,0000,0000,,Models can come from the media, Dialogue: 0,0:10:45.52,0:10:47.29,Default,,0000,0000,0000,,from our elected officials ... Dialogue: 0,0:10:47.97,0:10:51.06,Default,,0000,0000,0000,,Think of models of terrorism, Dialogue: 0,0:10:51.08,0:10:53.28,Default,,0000,0000,0000,,child kidnapping, Dialogue: 0,0:10:53.30,0:10:55.62,Default,,0000,0000,0000,,airline safety, car safety. Dialogue: 0,0:10:56.28,0:10:58.27,Default,,0000,0000,0000,,Models can come from industry. Dialogue: 0,0:10:59.09,0:11:02.31,Default,,0000,0000,0000,,The two I'm following\Nare surveillance cameras, Dialogue: 0,0:11:02.33,0:11:03.83,Default,,0000,0000,0000,,ID cards, Dialogue: 0,0:11:03.85,0:11:06.98,Default,,0000,0000,0000,,quite a lot of our computer\Nsecurity models come from there. Dialogue: 0,0:11:07.00,0:11:09.23,Default,,0000,0000,0000,,A lot of models come from science. Dialogue: 0,0:11:09.26,0:11:11.09,Default,,0000,0000,0000,,Health models are a great example. Dialogue: 0,0:11:11.12,0:11:14.14,Default,,0000,0000,0000,,Think of cancer, bird flu,\Nswine flu, SARS. Dialogue: 0,0:11:14.68,0:11:19.55,Default,,0000,0000,0000,,All of our feelings of security\Nabout those diseases Dialogue: 0,0:11:19.58,0:11:24.23,Default,,0000,0000,0000,,come from models given to us, really,\Nby science filtered through the media. Dialogue: 0,0:11:25.78,0:11:27.50,Default,,0000,0000,0000,,So models can change. Dialogue: 0,0:11:28.22,0:11:30.32,Default,,0000,0000,0000,,Models are not static. Dialogue: 0,0:11:30.35,0:11:33.59,Default,,0000,0000,0000,,As we become more comfortable\Nin our environments, Dialogue: 0,0:11:33.61,0:11:37.22,Default,,0000,0000,0000,,our model can move closer to our feelings. Dialogue: 0,0:11:38.70,0:11:41.04,Default,,0000,0000,0000,,So an example might be, Dialogue: 0,0:11:41.07,0:11:42.66,Default,,0000,0000,0000,,if you go back 100 years ago, Dialogue: 0,0:11:42.69,0:11:46.12,Default,,0000,0000,0000,,when electricity was first\Nbecoming common, Dialogue: 0,0:11:46.14,0:11:47.84,Default,,0000,0000,0000,,there were a lot of fears about it. Dialogue: 0,0:11:47.87,0:11:50.35,Default,,0000,0000,0000,,There were people who were afraid\Nto push doorbells, Dialogue: 0,0:11:50.37,0:11:53.38,Default,,0000,0000,0000,,because there was electricity\Nin there, and that was dangerous. Dialogue: 0,0:11:53.40,0:11:56.27,Default,,0000,0000,0000,,For us, we're very facile\Naround electricity. Dialogue: 0,0:11:56.29,0:11:59.11,Default,,0000,0000,0000,,We change light bulbs\Nwithout even thinking about it. Dialogue: 0,0:11:59.69,0:12:05.85,Default,,0000,0000,0000,,Our model of security around electricity\Nis something we were born into. Dialogue: 0,0:12:06.48,0:12:08.99,Default,,0000,0000,0000,,It hasn't changed as we were growing up. Dialogue: 0,0:12:09.01,0:12:10.58,Default,,0000,0000,0000,,And we're good at it. Dialogue: 0,0:12:12.12,0:12:16.62,Default,,0000,0000,0000,,Or think of the risks on the Internet\Nacross generations -- Dialogue: 0,0:12:16.64,0:12:18.74,Default,,0000,0000,0000,,how your parents approach\NInternet security, Dialogue: 0,0:12:18.76,0:12:20.38,Default,,0000,0000,0000,,versus how you do, Dialogue: 0,0:12:20.40,0:12:21.95,Default,,0000,0000,0000,,versus how our kids will. Dialogue: 0,0:12:23.04,0:12:25.59,Default,,0000,0000,0000,,Models eventually fade\Ninto the background. Dialogue: 0,0:12:27.17,0:12:29.66,Default,,0000,0000,0000,,"Intuitive" is just\Nanother word for familiar. Dialogue: 0,0:12:30.63,0:12:34.48,Default,,0000,0000,0000,,So as your model is close to reality\Nand it converges with feelings, Dialogue: 0,0:12:34.50,0:12:36.42,Default,,0000,0000,0000,,you often don't even know it's there. Dialogue: 0,0:12:37.98,0:12:41.80,Default,,0000,0000,0000,,A nice example of this came\Nfrom last year and swine flu. Dialogue: 0,0:12:43.02,0:12:45.02,Default,,0000,0000,0000,,When swine flu first appeared, Dialogue: 0,0:12:45.04,0:12:47.66,Default,,0000,0000,0000,,the initial news caused\Na lot of overreaction. Dialogue: 0,0:12:48.30,0:12:50.28,Default,,0000,0000,0000,,Now, it had a name, Dialogue: 0,0:12:50.30,0:12:52.35,Default,,0000,0000,0000,,which made it scarier\Nthan the regular flu, Dialogue: 0,0:12:52.38,0:12:53.94,Default,,0000,0000,0000,,even though it was more deadly. Dialogue: 0,0:12:54.52,0:12:57.73,Default,,0000,0000,0000,,And people thought doctors\Nshould be able to deal with it. Dialogue: 0,0:12:58.20,0:13:00.72,Default,,0000,0000,0000,,So there was that feeling\Nof lack of control. Dialogue: 0,0:13:00.75,0:13:03.86,Default,,0000,0000,0000,,And those two things\Nmade the risk more than it was. Dialogue: 0,0:13:03.88,0:13:07.44,Default,,0000,0000,0000,,As the novelty wore off\Nand the months went by, Dialogue: 0,0:13:07.46,0:13:10.30,Default,,0000,0000,0000,,there was some amount of tolerance;\Npeople got used to it. Dialogue: 0,0:13:11.10,0:13:13.76,Default,,0000,0000,0000,,There was no new data,\Nbut there was less fear. Dialogue: 0,0:13:14.42,0:13:16.60,Default,,0000,0000,0000,,By autumn, Dialogue: 0,0:13:16.62,0:13:20.00,Default,,0000,0000,0000,,people thought the doctors\Nshould have solved this already. Dialogue: 0,0:13:20.46,0:13:22.42,Default,,0000,0000,0000,,And there's kind of a bifurcation: Dialogue: 0,0:13:22.45,0:13:28.20,Default,,0000,0000,0000,,people had to choose\Nbetween fear and acceptance -- Dialogue: 0,0:13:29.25,0:13:30.90,Default,,0000,0000,0000,,actually, fear and indifference -- Dialogue: 0,0:13:30.92,0:13:32.72,Default,,0000,0000,0000,,and they kind of chose suspicion. Dialogue: 0,0:13:33.85,0:13:36.96,Default,,0000,0000,0000,,And when the vaccine appeared last winter, Dialogue: 0,0:13:36.98,0:13:39.50,Default,,0000,0000,0000,,there were a lot of people --\Na surprising number -- Dialogue: 0,0:13:39.52,0:13:41.32,Default,,0000,0000,0000,,who refused to get it. Dialogue: 0,0:13:43.52,0:13:47.17,Default,,0000,0000,0000,,And it's a nice example of how\Npeople's feelings of security change, Dialogue: 0,0:13:47.20,0:13:48.80,Default,,0000,0000,0000,,how their model changes, Dialogue: 0,0:13:48.82,0:13:50.49,Default,,0000,0000,0000,,sort of wildly, Dialogue: 0,0:13:50.52,0:13:53.29,Default,,0000,0000,0000,,with no new information,\Nwith no new input. Dialogue: 0,0:13:55.07,0:13:56.88,Default,,0000,0000,0000,,This kind of thing happens a lot. Dialogue: 0,0:13:57.94,0:13:59.91,Default,,0000,0000,0000,,I'm going to give one more complication. Dialogue: 0,0:13:59.93,0:14:02.63,Default,,0000,0000,0000,,We have feeling, model, reality. Dialogue: 0,0:14:03.38,0:14:05.89,Default,,0000,0000,0000,,I have a very relativistic\Nview of security. Dialogue: 0,0:14:05.91,0:14:07.73,Default,,0000,0000,0000,,I think it depends on the observer. Dialogue: 0,0:14:08.44,0:14:13.60,Default,,0000,0000,0000,,And most security decisions\Nhave a variety of people involved. Dialogue: 0,0:14:14.53,0:14:21.07,Default,,0000,0000,0000,,And stakeholders with specific trade-offs\Nwill try to influence the decision. Dialogue: 0,0:14:21.10,0:14:22.78,Default,,0000,0000,0000,,And I call that their agenda. Dialogue: 0,0:14:24.25,0:14:27.74,Default,,0000,0000,0000,,And you see agenda --\Nthis is marketing, this is politics -- Dialogue: 0,0:14:28.22,0:14:31.26,Default,,0000,0000,0000,,trying to convince you to have\None model versus another, Dialogue: 0,0:14:31.28,0:14:33.27,Default,,0000,0000,0000,,trying to convince you to ignore a model Dialogue: 0,0:14:33.29,0:14:35.96,Default,,0000,0000,0000,,and trust your feelings, Dialogue: 0,0:14:35.99,0:14:38.49,Default,,0000,0000,0000,,marginalizing people\Nwith models you don't like. Dialogue: 0,0:14:39.48,0:14:41.00,Default,,0000,0000,0000,,This is not uncommon. Dialogue: 0,0:14:42.35,0:14:45.58,Default,,0000,0000,0000,,An example, a great example,\Nis the risk of smoking. Dialogue: 0,0:14:46.94,0:14:48.72,Default,,0000,0000,0000,,In the history of the past 50 years, Dialogue: 0,0:14:48.74,0:14:51.36,Default,,0000,0000,0000,,the smoking risk shows\Nhow a model changes, Dialogue: 0,0:14:51.38,0:14:55.74,Default,,0000,0000,0000,,and it also shows how an industry fights\Nagainst a model it doesn't like. Dialogue: 0,0:14:56.72,0:14:59.83,Default,,0000,0000,0000,,Compare that to the secondhand\Nsmoke debate -- Dialogue: 0,0:14:59.85,0:15:01.80,Default,,0000,0000,0000,,probably about 20 years behind. Dialogue: 0,0:15:02.72,0:15:04.34,Default,,0000,0000,0000,,Think about seat belts. Dialogue: 0,0:15:04.36,0:15:06.38,Default,,0000,0000,0000,,When I was a kid, no one wore a seat belt. Dialogue: 0,0:15:06.41,0:15:09.95,Default,,0000,0000,0000,,Nowadays, no kid will let you drive\Nif you're not wearing a seat belt. Dialogue: 0,0:15:11.37,0:15:13.83,Default,,0000,0000,0000,,Compare that to the airbag debate, Dialogue: 0,0:15:13.85,0:15:15.52,Default,,0000,0000,0000,,probably about 30 years behind. Dialogue: 0,0:15:16.75,0:15:18.83,Default,,0000,0000,0000,,All examples of models changing. Dialogue: 0,0:15:21.60,0:15:24.39,Default,,0000,0000,0000,,What we learn is that changing\Nmodels is hard. Dialogue: 0,0:15:25.07,0:15:27.13,Default,,0000,0000,0000,,Models are hard to dislodge. Dialogue: 0,0:15:27.15,0:15:28.83,Default,,0000,0000,0000,,If they equal your feelings, Dialogue: 0,0:15:28.85,0:15:30.75,Default,,0000,0000,0000,,you don't even know you have a model. Dialogue: 0,0:15:31.85,0:15:33.74,Default,,0000,0000,0000,,And there's another cognitive bias Dialogue: 0,0:15:33.76,0:15:35.83,Default,,0000,0000,0000,,I'll call confirmation bias, Dialogue: 0,0:15:35.85,0:15:40.21,Default,,0000,0000,0000,,where we tend to accept data\Nthat confirms our beliefs Dialogue: 0,0:15:40.24,0:15:42.67,Default,,0000,0000,0000,,and reject data\Nthat contradicts our beliefs. Dialogue: 0,0:15:44.23,0:15:48.16,Default,,0000,0000,0000,,So evidence against our model,\Nwe're likely to ignore, Dialogue: 0,0:15:48.19,0:15:49.44,Default,,0000,0000,0000,,even if it's compelling. Dialogue: 0,0:15:49.46,0:15:52.47,Default,,0000,0000,0000,,It has to get very compelling\Nbefore we'll pay attention. Dialogue: 0,0:15:53.73,0:15:56.33,Default,,0000,0000,0000,,New models that extend\Nlong periods of time are hard. Dialogue: 0,0:15:56.35,0:15:58.10,Default,,0000,0000,0000,,Global warming is a great example. Dialogue: 0,0:15:58.13,0:16:01.57,Default,,0000,0000,0000,,We're terrible at models\Nthat span 80 years. Dialogue: 0,0:16:01.60,0:16:03.66,Default,,0000,0000,0000,,We can do "to the next harvest." Dialogue: 0,0:16:03.68,0:16:05.99,Default,,0000,0000,0000,,We can often do "until our kids grow up." Dialogue: 0,0:16:06.50,0:16:08.70,Default,,0000,0000,0000,,But "80 years," we're just not good at. Dialogue: 0,0:16:09.72,0:16:12.02,Default,,0000,0000,0000,,So it's a very hard model to accept. Dialogue: 0,0:16:12.74,0:16:15.68,Default,,0000,0000,0000,,We can have both models\Nin our head simultaneously -- Dialogue: 0,0:16:16.65,0:16:23.60,Default,,0000,0000,0000,,that kind of problem where\Nwe're holding both beliefs together, Dialogue: 0,0:16:23.62,0:16:24.99,Default,,0000,0000,0000,,the cognitive dissonance. Dialogue: 0,0:16:25.02,0:16:28.17,Default,,0000,0000,0000,,Eventually, the new model\Nwill replace the old model. Dialogue: 0,0:16:28.90,0:16:31.09,Default,,0000,0000,0000,,Strong feelings can create a model. Dialogue: 0,0:16:32.15,0:16:37.51,Default,,0000,0000,0000,,September 11 created a security model\Nin a lot of people's heads. Dialogue: 0,0:16:37.54,0:16:40.83,Default,,0000,0000,0000,,Also, personal experiences\Nwith crime can do it, Dialogue: 0,0:16:40.85,0:16:42.23,Default,,0000,0000,0000,,personal health scare, Dialogue: 0,0:16:42.25,0:16:43.72,Default,,0000,0000,0000,,a health scare in the news. Dialogue: 0,0:16:44.94,0:16:48.28,Default,,0000,0000,0000,,You'll see these called\N"flashbulb events" by psychiatrists. Dialogue: 0,0:16:48.92,0:16:51.38,Default,,0000,0000,0000,,They can create a model instantaneously, Dialogue: 0,0:16:51.41,0:16:53.17,Default,,0000,0000,0000,,because they're very emotive. Dialogue: 0,0:16:54.65,0:16:56.24,Default,,0000,0000,0000,,So in the technological world, Dialogue: 0,0:16:56.26,0:16:59.50,Default,,0000,0000,0000,,we don't have experience to judge models. Dialogue: 0,0:16:59.86,0:17:02.80,Default,,0000,0000,0000,,And we rely on others. We rely on proxies. Dialogue: 0,0:17:02.82,0:17:05.44,Default,,0000,0000,0000,,And this works, as long as\Nit's the correct others. Dialogue: 0,0:17:05.92,0:17:08.60,Default,,0000,0000,0000,,We rely on government agencies Dialogue: 0,0:17:08.63,0:17:13.03,Default,,0000,0000,0000,,to tell us what pharmaceuticals are safe. Dialogue: 0,0:17:13.06,0:17:14.97,Default,,0000,0000,0000,,I flew here yesterday. Dialogue: 0,0:17:14.99,0:17:16.76,Default,,0000,0000,0000,,I didn't check the airplane. Dialogue: 0,0:17:17.44,0:17:20.03,Default,,0000,0000,0000,,I relied on some other group Dialogue: 0,0:17:20.06,0:17:22.50,Default,,0000,0000,0000,,to determine whether\Nmy plane was safe to fly. Dialogue: 0,0:17:22.52,0:17:25.82,Default,,0000,0000,0000,,We're here, none of us fear the roof\Nis going to collapse on us, Dialogue: 0,0:17:25.84,0:17:28.05,Default,,0000,0000,0000,,not because we checked, Dialogue: 0,0:17:28.07,0:17:31.74,Default,,0000,0000,0000,,but because we're pretty sure\Nthe building codes here are good. Dialogue: 0,0:17:33.18,0:17:36.17,Default,,0000,0000,0000,,It's a model we just accept Dialogue: 0,0:17:36.20,0:17:37.56,Default,,0000,0000,0000,,pretty much by faith. Dialogue: 0,0:17:38.07,0:17:39.43,Default,,0000,0000,0000,,And that's OK. Dialogue: 0,0:17:42.71,0:17:48.58,Default,,0000,0000,0000,,Now, what we want is people\Nto get familiar enough with better models, Dialogue: 0,0:17:48.60,0:17:50.72,Default,,0000,0000,0000,,have it reflected in their feelings, Dialogue: 0,0:17:50.75,0:17:53.75,Default,,0000,0000,0000,,to allow them to make security trade-offs. Dialogue: 0,0:17:54.85,0:17:58.57,Default,,0000,0000,0000,,When these go out of whack,\Nyou have two options. Dialogue: 0,0:17:58.59,0:18:02.83,Default,,0000,0000,0000,,One, you can fix people's feelings,\Ndirectly appeal to feelings. Dialogue: 0,0:18:02.85,0:18:05.26,Default,,0000,0000,0000,,It's manipulation, but it can work. Dialogue: 0,0:18:05.91,0:18:08.10,Default,,0000,0000,0000,,The second, more honest way Dialogue: 0,0:18:08.13,0:18:09.90,Default,,0000,0000,0000,,is to actually fix the model. Dialogue: 0,0:18:11.46,0:18:13.56,Default,,0000,0000,0000,,Change happens slowly. Dialogue: 0,0:18:13.58,0:18:17.96,Default,,0000,0000,0000,,The smoking debate took 40 years --\Nand that was an easy one. Dialogue: 0,0:18:19.94,0:18:21.75,Default,,0000,0000,0000,,Some of this stuff is hard. Dialogue: 0,0:18:22.24,0:18:25.99,Default,,0000,0000,0000,,Really, though, information\Nseems like our best hope. Dialogue: 0,0:18:26.02,0:18:27.29,Default,,0000,0000,0000,,And I lied. Dialogue: 0,0:18:27.31,0:18:31.33,Default,,0000,0000,0000,,Remember I said feeling, model, reality;\Nreality doesn't change? Dialogue: 0,0:18:31.36,0:18:32.73,Default,,0000,0000,0000,,It actually does. Dialogue: 0,0:18:32.76,0:18:34.47,Default,,0000,0000,0000,,We live in a technological world; Dialogue: 0,0:18:34.49,0:18:36.83,Default,,0000,0000,0000,,reality changes all the time. Dialogue: 0,0:18:37.63,0:18:40.60,Default,,0000,0000,0000,,So we might have,\Nfor the first time in our species: Dialogue: 0,0:18:40.63,0:18:43.81,Default,,0000,0000,0000,,feeling chases model, model chases\Nreality, reality's moving -- Dialogue: 0,0:18:43.84,0:18:45.37,Default,,0000,0000,0000,,they might never catch up. Dialogue: 0,0:18:46.92,0:18:48.25,Default,,0000,0000,0000,,We don't know. Dialogue: 0,0:18:50.35,0:18:51.96,Default,,0000,0000,0000,,But in the long term, Dialogue: 0,0:18:51.98,0:18:54.18,Default,,0000,0000,0000,,both feeling and reality are important. Dialogue: 0,0:18:54.21,0:18:57.44,Default,,0000,0000,0000,,And I want to close with two quick\Nstories to illustrate this. Dialogue: 0,0:18:57.47,0:18:59.94,Default,,0000,0000,0000,,1982 -- I don't know if people\Nwill remember this -- Dialogue: 0,0:18:59.97,0:19:03.34,Default,,0000,0000,0000,,there was a short epidemic\Nof Tylenol poisonings Dialogue: 0,0:19:03.36,0:19:04.56,Default,,0000,0000,0000,,in the United States. Dialogue: 0,0:19:04.58,0:19:05.94,Default,,0000,0000,0000,,It's a horrific story. Dialogue: 0,0:19:05.97,0:19:08.05,Default,,0000,0000,0000,,Someone took a bottle of Tylenol, Dialogue: 0,0:19:08.07,0:19:11.07,Default,,0000,0000,0000,,put poison in it, closed it up,\Nput it back on the shelf, Dialogue: 0,0:19:11.10,0:19:12.66,Default,,0000,0000,0000,,someone else bought it and died. Dialogue: 0,0:19:12.68,0:19:14.35,Default,,0000,0000,0000,,This terrified people. Dialogue: 0,0:19:14.38,0:19:16.60,Default,,0000,0000,0000,,There were a couple of copycat attacks. Dialogue: 0,0:19:16.63,0:19:19.47,Default,,0000,0000,0000,,There wasn't any real risk,\Nbut people were scared. Dialogue: 0,0:19:19.50,0:19:23.37,Default,,0000,0000,0000,,And this is how the tamper-proof\Ndrug industry was invented. Dialogue: 0,0:19:23.40,0:19:25.62,Default,,0000,0000,0000,,Those tamper-proof caps?\NThat came from this. Dialogue: 0,0:19:25.65,0:19:27.22,Default,,0000,0000,0000,,It's complete security theater. Dialogue: 0,0:19:27.24,0:19:30.14,Default,,0000,0000,0000,,As a homework assignment,\Nthink of 10 ways to get around it. Dialogue: 0,0:19:30.16,0:19:32.05,Default,,0000,0000,0000,,I'll give you one: a syringe. Dialogue: 0,0:19:32.07,0:19:34.86,Default,,0000,0000,0000,,But it made people feel better. Dialogue: 0,0:19:35.48,0:19:39.19,Default,,0000,0000,0000,,It made their feeling of security\Nmore match the reality. Dialogue: 0,0:19:40.13,0:19:43.06,Default,,0000,0000,0000,,Last story: a few years ago,\Na friend of mine gave birth. Dialogue: 0,0:19:43.09,0:19:44.48,Default,,0000,0000,0000,,I visit her in the hospital. Dialogue: 0,0:19:44.51,0:19:46.43,Default,,0000,0000,0000,,It turns out, when a baby's born now, Dialogue: 0,0:19:46.46,0:19:50.02,Default,,0000,0000,0000,,they put an RFID bracelet on the baby,\Na corresponding one on the mother, Dialogue: 0,0:19:50.04,0:19:53.66,Default,,0000,0000,0000,,so if anyone other than the mother takes\Nthe baby out of the maternity ward, Dialogue: 0,0:19:53.69,0:19:54.84,Default,,0000,0000,0000,,an alarm goes off. Dialogue: 0,0:19:54.87,0:19:56.60,Default,,0000,0000,0000,,I said, "Well, that's kind of neat. Dialogue: 0,0:19:56.62,0:20:00.59,Default,,0000,0000,0000,,I wonder how rampant\Nbaby snatching is out of hospitals." Dialogue: 0,0:20:00.62,0:20:01.85,Default,,0000,0000,0000,,I go home, I look it up. Dialogue: 0,0:20:01.88,0:20:03.40,Default,,0000,0000,0000,,It basically never happens. Dialogue: 0,0:20:03.42,0:20:05.27,Default,,0000,0000,0000,,(Laughter) Dialogue: 0,0:20:05.29,0:20:08.14,Default,,0000,0000,0000,,But if you think about it,\Nif you are a hospital, Dialogue: 0,0:20:08.16,0:20:10.54,Default,,0000,0000,0000,,and you need to take a baby\Naway from its mother, Dialogue: 0,0:20:10.56,0:20:12.34,Default,,0000,0000,0000,,out of the room to run some tests, Dialogue: 0,0:20:12.37,0:20:14.42,Default,,0000,0000,0000,,you better have some good\Nsecurity theater, Dialogue: 0,0:20:14.44,0:20:16.39,Default,,0000,0000,0000,,or she's going to rip your arm off. Dialogue: 0,0:20:16.41,0:20:17.94,Default,,0000,0000,0000,,(Laughter) Dialogue: 0,0:20:18.90,0:20:20.62,Default,,0000,0000,0000,,So it's important for us, Dialogue: 0,0:20:20.64,0:20:22.78,Default,,0000,0000,0000,,those of us who design security, Dialogue: 0,0:20:22.80,0:20:24.83,Default,,0000,0000,0000,,who look at security policy -- Dialogue: 0,0:20:25.69,0:20:28.99,Default,,0000,0000,0000,,or even look at public policy\Nin ways that affect security. Dialogue: 0,0:20:29.75,0:20:33.16,Default,,0000,0000,0000,,It's not just reality;\Nit's feeling and reality. Dialogue: 0,0:20:33.19,0:20:35.05,Default,,0000,0000,0000,,What's important Dialogue: 0,0:20:35.08,0:20:36.62,Default,,0000,0000,0000,,is that they be about the same. Dialogue: 0,0:20:36.64,0:20:39.18,Default,,0000,0000,0000,,It's important that,\Nif our feelings match reality, Dialogue: 0,0:20:39.20,0:20:41.07,Default,,0000,0000,0000,,we make better security trade-offs. Dialogue: 0,0:20:41.45,0:20:42.60,Default,,0000,0000,0000,,Thank you. Dialogue: 0,0:20:42.63,0:20:44.76,Default,,0000,0000,0000,,(Applause)