User education is pointless
“It really is a nightmare. User education is a complete waste of time. It is about as much use as nailing jelly to a wall,” Overton said. “There is no good trying to teach them what phishing is, what rootkits are, what malware is, etc. They are not interested; they just want to do their job.”
[…]
Jill Sitherwood, an information security consultant at a large financial institution, has seen education both fail and succeed. “I have to believe it works,” she said. “When we give our awareness presentations, what signs to look for, I have seen a spike in the number of incidents reported by our internal users.”
But online consumers are a tougher crowd to get through to.
“We have a special page on our Web site to report security incidents. We had to shut the e-mail box because customers didn’t read (the page) and submitted general customer service queries,” Sitherwood said.
I have been saying for years that most people are too stupid to be safely allowed near a computer, and for years I have been getting criticized for saying so. When computers can be made as safe to use — safe for the user, safe for the machine, and safe for the rest of the world — as a VCR, then and only then should they be placed in the hands of an average person. And even then, there will still be a significant number of people for whom the time will always blink .