I agree that the majority of compromised systems and spam relays have Dynamic IPs. However, that is not the same thing as saying, the majority of Dynamic IP systems send spam, or are open relays. Two different statements. That's why I don't agree with blanket blocking of Dynamic IPs. As a side note, this is the first time you mentioned Dynamic IPs. Up to now we were talking about "residential" IPs. Do you consider the terms synonymous?
Disagree. But that's okay.
You could stop even more if you blocked even more. I don't see that as surprising. You do this after making a conscious decision to accept more "false positive" losses. Again, your choice, but not for everyone.
Well, not saying that you don't have a clue, only that this analogy doesn't prove that you do. After all, it's easy to avoid having a compromised customer, just block everything. Doesn't mean it was a smart solution for that particular customer just because he wasn't hacked.
I have had this responsibility as an admin and eventually as a manager of an IT group in a major Aerospace Corp. But, as a manager, I had much more responsibility than this. I also had responsibility to ensure company business could be successfully conducted and that my engineers had the tools and connectivity they needed to be successful and make our company successful. I had to do risk analysis on most every major configuration decision. And that is the KEY. Risk analysis. You have to weigh the potential risk (including potential loss if something goes wrong) with the potential impact on operations (often spelled reduced income). There are some cases where this kind of security is necessary, I know. And if it means throwing some of the babies out with the bathwater, it can be justified, sometimes. I used to see this all the time in the realm of "National Security". However, to think that all (or most) systems would benefit by using security measures this tight is ludicrous to me.
Not to be argumentative. I understand that different folks have different philosophies. I think we are both entitled to our own, no problem :)
-Frank