note that the quote wasn't mine ... i found it in recent (san fran chronicle) newspaper article titled "Banks must come clean on ID theft" and posted the reference
http://www.garlic.com/~lynn/2007h.html#48 Securing financial transactions a high priority for 2007
http://www.garlic.com/~lynn/aadsm26.htm#58 Our security sucks. Why can't we change? What's wrong with us?
although I did note that in a couple posts from last month I had observed the relatively vast differences in various articles on how recent fraud numbers were interpreted.
http://www.garlic.com/~lynn/2007e.html#29 Securing financial transactions a high priority for 2007
http://www.garlic.com/~lynn/2007e.html#62 Securing financial transactions a high priority for 2007
now today there are references to recent Schneier article:
Bad Security Driving Out the Good
http://it.slashdot.org/it/07/04/19/140245.shtml
How Security Companies Sucker Us With Lemons
http://www.wired.com/politics/security/commentary/securitymatters/2007/04/securitymatters_0419?currentPage=all
and for a little more drift, there is recent thread topic drift related to nothing succeeds like failure
http://www.garlic.com/~lynn/2007h.html#29 sizeof() was: The Perfect Computer - 36 bits?
http://www.garlic.com/~lynn/2007h.html#33 sizeof() was: The Perfect Computer - 36 bits?
as well as somewhat similar reference in recent risk digest
http://catless.ncl.ac.uk/Risks/24.62.html