The title describes a Security approach. According to this approach the easiest and most plausible Security breach is by usage of the weakest link. Lessons learned from few Penetration Tests I conducted, support the cited above approach. It is true that there is no way to assure absolute Security (For deeper explanation why you can look at a well known security Guru, Bruce Schnirer's web site ). A ny Security mechanism is breakable by someone who has expertise and spends a lot of resources (including time). But it is also possible to breach Security without expertise and by spending only few resources for a very short time: just exploit the weakest link . As part of a Penetration Test, I always looked for simple unsophisticated methods to penetrate instead of penetrating by usage of very sophisticated methods. These methods could be used by anyone, unlike the sophisticated ones, which could be used only by a limited group of very talented experts. ...
Blog on SOA, Cloud Computing and other IT architectural issues, technologies and trends.