>> -----Original Message-----
>> From:
david@lang.hm [mailto:david@lang.hm]
>>> The problem is that you have to account for the cases where the
> malware
>>> made it onto the system even if you were trying to catch it ahead of
>>> time. For example:
>>>
>>> - Administrator turns off or reduces AV protection for some reason
> for
>>> some period of time. It happens all the time.
>>
>> according to the threat model actions of the administrator do not
> matter.
>
> Sorry, I don't know what you mean.