> While I think you have a point I also think Ethan has one too. It
> is important to remember that users are generally clueless and/or
> unconcerned with security. Of course I'm grossly generalizing but I
> think you get my point.
Yes, I can agree with that...I do get the point. But who are the
users? Say you're an admin at a law firm...if the users are supposed
to be security-conscious (face it, a great many admins lack even the
most rudimentary security awareness), then shouldn't the admins be
required to have a law degree, also? How about a hospital...shouldn't
each admin then have to have a medical degree?