Noam Epple of Vivica Information Security Inc. believes the info sec community has failed. Understandably, I take issue with this. Thomas Ptacek has a nice reply which highlights the mistake Noam has made: You can't look at every problem and claim that security has failed, if there is an effective defence. You can claim there are a lot of people being dumb and not using the defence, but we knew that already, hence our continued employment.
To provide an analogy, if I said that physical lock security has failed due to the number of thefts reported each year, I would be fiddling the stats. A meaningful stat would be to look at the number of thefts that occurred in situations where the goods had been properly secured.
This is not to say every security problem has been solved, but rather that a claim of "Complete, Unquestionable, and Total" failure is overblown to say the least.
I think there is an interesting correlation between the number of adjectives used in a story title and the quality of an article :)