5 ms·
Not Linux specific but: Don’t make your security encourage legitimate users to work around it due to pointless friction
by fyjvd90 8y ago
Not Linux specific but:
Don’t make your security encourage legitimate users to work around it due to pointless friction
- tyingq 8y agoThat's a pretty good description of apparmor.
- torvolt 8y agoI always felt like increasing security has some cost on convenience.
- geofft 8y agoIt shifts convenience. It's less convenient for me to have to unlock my door when I get home, but it's more convenient to not carry all my valuables with me during the day. And I really like that tradeoff. Good security measures are like this. Add sandboxes so you can let users do what they want. Add authentication so people know who they're talking to. Support security keys so people don't have to worry ad much about being phished. And so forth.
- fyjvd90 8y agoIt does, but there’s also what I call stupid security that doesn’t really add any measurable improvement, but does decrease productivity. Users out smart these systems all the time (e.g. forced password changes where you can’t use the last 10 passwords, users just change their password 11 times so they can continue to use a password that’s been configured on their devices. It’s stupid then to force changes like that when there are much better ways like mfa) Smart security allows users to do what they need to do efficiently and safely.
- llama052 8y agoYeah I can't stand the forced password changes where you can't use the last X passwords, or passwords that expire every 30 days. A lot of times it's security compliance entities that push this down to companies, for instance PCI, etc all require those. I think even the new NIST standards address these practices, but the compliance entities are slow and far from pragmatic.
- mises 8y agoYep. I can tell you that currently, leading practice involves such measures. I don't agree, but CIS, which is essentially the current gold standard, says so. People who get paid to do this often don't bother griping about it, because they are being paid to harden to a standard and that standard is what it is. This unfortunately leaves a disconnect between the people who harden (who might actually hear about issues), and the people who write. Even if the writers do hear, it won't be implemented until the next revision.
- techslave 8y agoyes but the rule does enhance security. the password rules force you to choose [heuristically] guessable passwords, therefore they must be changed every 90 days. simple!
- xorgar831 8y agoIt doesn't if users are working around it.
- cwyers 8y agoRight. The first rule of password security: if you have a large enough user base, the odds of a user writing down a password increase, and as passwords become sufficiently difficult to remember, the odds approach 100% at some point that _some_ people are writing down passwords. No amount of defense in depth can protect the "I have a Post-It note under my keyboard" problem, if people can get into your building.
- shaftoe 8y agoWe've handled this by mandating password manager use and pushing length requirements to absurd levels to where it truly is easier to just use the manager, which has two factor.
- fyjvd90 8y agoYeah PCI or FedRAMP have this 10 char password requirement, which of course no one can remember a 10 char password. So companies just make the password a pattern with some variations, effectively reducing the complexity to a tenth of a random 8 char password and the people who know the pattern leave the company so it’s effectively public. So much for math.
- dragonwriter 8y agoUsability is a component of security because of human factors; if your “secure” process or system is not convenient for use, people will in practice find ways to work around it instead of using it as intended, which will defeat security.
- bigiain 8y agoOften, but not always. ssh keys instead of passwords are a good example of better security and more convenience (for the most common use cases). It'd be nice if more "security improvements" came with ways to make them convenience improvements too...
- gerdesj 8y agoAbsolutely, but I prefer not to leave 22/tcp open to the world. If I do leave it open it is only from a restricted IP set, otherwise it is behind a VPN, probably OpenVPN.
- closeparen 8y agoIs OpenVPN a safer attack surface compared to OpenSSH?
- aaronmdjones 8y agoI doubt it.
- amdavidson 8y agoIs OpenSSH safer when used in addition to OpenVPN? Probably.
- romeisendcoming 8y agoSure, especially when you VPN into a sacrificial subnet and need MFA to continue elsewhere into locked down application domains. OTOH I would leave ssh listening on a non-descript high port with MFA (key and OTP) enabled. No use worrying too much about that.
- techbio 8y agoAlso, have a way for those efficient users to alert you to their pain points (and make it easier than the workaround).
- bogomipz 8y agoBeyond a certain point I think that's true. There's an old adage that "security is inversely proportional to convenience."
- Rapzid 8y agoA policy adhered to is better than a policy not.
- fencepost 8y agoThat's why for any office that has internal wifi I encourage also having a "guest" wifi network (small offices, not using anything with enterprise-level management). People are going to want to connect devices to wifi instead of LTE even if they never approach their billing limits, and if there's an available option that they're allowed to use it cuts down on attempts to use the one they're restricted from (and complaints about "I tried to connect to the wifi but I can't get to the Internet!" "Was it the internal one or the guest? Internal is locked down. Connect to the guest.")