4 ms·
I think completely the opposite. The sooner we can stop depending on the user to behave a certain way so that we can be secure, the better. We told users for y
by Scott_Helme_ 9y ago
I think completely the opposite. The sooner we can stop depending on the user to behave a certain way so that we can be secure, the better.
We told users for years to look for a padlock and https in the address bar before entering passwords or credit card details to make sure it was encrypted. Now we have HSTS so that websites can enforce https without having to have the user manually check things and risk missing something. HSTS does not place a burden on the user, we took responsibility from the user and fixed the issue without having to involve them. That's exactly how we improve security.
Clicking links in emails is another prime example. We can try to teach the user as much as we like for as long as we like but ultimately there's almost 8 billion people on Earth, so yeah, good luck on that front! Instead we can enforce policies like SPF/DKIM/DMARC to ensure the sender is genuine, check the reputation of domains linked in the body and filter them, scan attachments for malicious content, prevent execution of scripts, remove administrative privileges from the user and countless other technical measures we can deploy without even having to speak to the user once.
Every time we have to ask the user to do something or to not do something, the technology has failed.