3 ms·
Not sure what you mean. Nothing is secure, ever, in a binary sense of being just one thing or the other. It's all a balance between level of security and level
by themarkn 8y ago
Not sure what you mean. Nothing is secure, ever, in a binary sense of being just one thing or the other. It's all a balance between level of security and level of practical usability. Often we've made things easy to use but hard to secure. Like SSNs. But regardless of the source of an attack, the reward for breaking 1 billion targets on the same system vs 1.3 million on a different system is probably much higher. So the inconveniences of more secure systems must be weighed in context of the desirability of the information within them. More attractive targets need more secure, less easy to use, systems.
- dvdkon 8y ago> More attractive targets need more secure, less easy to use, systems. That seems to me like a justification for doing the least amount of work needed. Sure, it's true to some degree, but (taking this case as an example) PKI is objectively uncountably better than a PSK-like structure. There's a base security level and until that's reached, there's no need to expend money and time or inconvenience users to gain greater security. Anyone who doesn't get to that level while designing a project of any importance is a lazy idiot.
- themarkn 8y agoYeah this is a fair point, didn't mean to suggest that easy security wins that dont't inconvenience the user or add cost in some other way aren't worth making.
- xg15 8y ago> More attractive targets need more secure, less easy to use, systems. Actually, it needs to be both secure and easy to use to work.