RD> When one has a network/system in which the basic security BCPs
RD> haven't been implemented, it makes little sense to expend scarce
RD> resources testing when those resources could be better-employed
RD> hardening and increasing the resiliency and robustness of said
RD> network/system.

Very true.  "Hey, it really _did_ break!" is hardly a useful approach.

Your post awakened my inner cynic: Perhaps there are people who look to
stress-testing OPNs in hopes that the weakest link is elsewhere, so that
they may point the proverbial finger instead of fixing internal

#include "cost-shifting/patchining,smtp-auth,spf,urpf,et-cetera.h"

