4 ms·
Yeah, there's no accounting for glaring cluelessness. Leaving S3 buckets open to the world, and totally unencrypted, for example. Downloading and running *.exe
by laurentMiguel 8y ago
Yeah, there's no accounting for glaring cluelessness. Leaving S3 buckets open to the world, and totally unencrypted, for example. Downloading and running *.exe email attachments, destroying systems with ransomware, and so on.
Encryption can be its own foot gun. It can aid attackers, by totally destroying evidence that might exonerate you from being framed for other crimes. It can cost people dearly, in terms of lost data. Consider how many people have lost old bitcoin wallets, containing small fortunes, and similar tails of woe.
But look at how that plays out. A dropped bitcoin wallet, gone forever. The failure mode of something like that is often a better look than things going the other way. Imagine that same bitcoin wallet getting stolen, and seeing the thief profit from it. Sort of like watching elections get stolen, no?
So, think about that, the next time you warn someone against forcing you to exchange PGP keys, in order to communicate more securely.
- tptacek 8y agoU2F keys were invented in part because the glaringly clueless employees at Google were routinely shown to be phishable. People who dismiss phishing as a threat vector betray a lack of understanding of how difficult it is to mitigate reliably.