Ok, I never said that the 'analysis' should be purely based on dollar value. I never even said it should be a mathematical model. You accuse me of a strawman and then turn around and do the same to me.
I was simply pointing out that we can never get to zero risk, and since we can't, we have to weigh risks based on consequences and probability.
> 1) fully examine the system for potential critical failure points/modes
Sure, to the best of your ability. How can you know for certain you have found all potential critical failure points? You can get pretty sure, but never fully sure. We still have industrial accidents, in every single industry in the world.
You also have to define what a 'critical risk' is. I don't think it is an a priori fact that accidentally sending a recording of a conversation to a contact is a 'critical risk'.
So your model isn't even mathematical, it's what, just a SWAG of the combined hazards and odds? That works for linear, small risks.
It absolutely does NOT work for serious risks, e.g., of death, serious injury, massive privacy violation, and other potential life-changing events.
The concept you are clearly avoiding or missing non-linear risk.
You (and amzn_engineer1) are advocating for simply subsuming risk assessment into the ordinary development cycle, and calling it "taking it seriously".
That is fooling yourself.
Taking it seriously is actually making full and serious effort OUT OF THE NORMAL DEVELOPMENT CYCLE for no other purpose than to SEEK and identify potential critical risks.
It is then engineering a variety of in-depth solutions to prevent those critical failure points from ever seeing the light of day. And implementing them. and testing them. And monitoring them.
>> I don't think it is an a priori fact that accidentally sending a recording of a conversation to a contact is a 'critical risk'.
This is an exact example of this sort of failure: 'it's not a priori bad'..., minimize it and streamline it into dev.
I really want to know in what world any sane person would say that it's OK to randomly divulging an intimate conversation to a contact or random recipient -- seriously, who would say that?
I mean sure, most conversations are benign, but some could be utterly life-changing if revealed. and that's OK with you?
I was simply pointing out that we can never get to zero risk, and since we can't, we have to weigh risks based on consequences and probability.
> 1) fully examine the system for potential critical failure points/modes
Sure, to the best of your ability. How can you know for certain you have found all potential critical failure points? You can get pretty sure, but never fully sure. We still have industrial accidents, in every single industry in the world.
You also have to define what a 'critical risk' is. I don't think it is an a priori fact that accidentally sending a recording of a conversation to a contact is a 'critical risk'.