26 ms·
EDIT: If this was crowd-funded (to help pay for the expert's time), I'd be happy to contribute. The reputation of this page emphasizes (epitomizes?) a need the
by hackuser 10y ago
EDIT: If this was crowd-funded (to help pay for the expert's time), I'd be happy to contribute.
The reputation of this page emphasizes (epitomizes?) a need the public has: An authoritative, accurate, comprehensive, usable security guide for non-technical end-users.
* Authoritative: There are too many pages, apps, and too much advice like the parent. Most end users - even most IT professionals, IMHO - have no good way to differentiate between good advice and bad. The solution is for one source of advice to become authoritative; i.e., it needs to be endorsed by people respected in the IT security industry and by names the public recognizes (e.g., the NY Times, ACLU, NRA, etc.). Its authority must stand out from the rest, and in a way the general public recognizes (endorsements on HN don't work), or it becomes just another voice among many.
* Accurate: Written by true IT security professionals who do real homework for it. Not IT pros or devs who read about security and have some sense of it. Not even by cryptographers who don't know the implementation side.
* Comprehensive: A one-stop shop. Otherwise, it loses authority and usefulness.
* Usable: Something non-technical end users can grasp and implement, as easily as possible. The harder it is, the fewer people will use it and the more people will misuse it (i.e., misunderstand it and make mistakes). 'Easily' also means affordably; telling everyone to buy iPhones may not be realistic.
Personally I wouldn't mind a guide for technical users, but that is a very secondary concern.