7 ms·
Curious, why would a doctor decline to use basic password auth?
by endothrowho333 7y ago
Curious, why would a doctor decline to use basic password auth?
- kjs3 7y agoI have had a doctor tell me that his time was too important to waste it typing passwords. I had another one tell me, quite dramatically, "someone could die" while he was typing in a password. It's a profession where many have an "interesting" perspective on information protection. I have tons of tragicomic security stories from dealing with health care providers.
- tialaramex 7y agoAnd they are right. Passwords are probably the wrong thing. Give the doctors a hardware token, a smartcard (and fit smartcard readers to everything doctors might expect to use) or use biometrics. Might some doctors leave the smartcard in the reader for a PC they often use, then walk away? Yes, yes they might, and that is a behaviour you can start fighting with peer pressure, but doctors are right to think passwords are a waste of their time.
- vageli 7y ago> And they are right. Passwords are probably the wrong thing. Give the doctors a hardware token, a smartcard (and fit smartcard readers to everything doctors might expect to use) or use biometrics. > Might some doctors leave the smartcard in the reader for a PC they often use, then walk away? Yes, yes they might, and that is a behaviour you can start fighting with peer pressure, but doctors are right to think passwords are a waste of their time. At least the hospitals I've been to this is implemented as an rfid tag on their id badge, so it doubles as access control both for physical and software systems (as well as functioning as a charge card of sorts against the employee's company account for things like the cafeteria).
- txcwpalpha 7y ago>And they are right. Passwords are probably the wrong thing. Give the doctors a hardware token, a smartcard (and fit smartcard readers to everything doctors might expect to use) or use biometrics. This is spot on and in most cases this is the way most hospitals are moving, particularly by using the already-assigned ID badges as RFID tokens. But as I mentioned in a couple of other comments farther down, I have experienced situations in which even this is something that doctors refuse (in one case, because they were upset that we were asking them to keep their ID badge with them, which they apparently had a problem with doing). It's the most frictionless solution I've seen in widespread adoption and probably the least prone to pushback, but that doesn't mean there's no pushback, which is the unfortunate point of my original comment at the top of the thread.
- matz1 7y agoYes password are annoyance, friction and waste of time. Not to mention 2FA that is worse. For the Dr, his upmost concern is to treat the patient not deal with extra layer of annoyance. As an IT or security personel your job is to support them and assure security without creating extra friction or productivity loss. Yes it is hard but that is the challenge. This is what a often neglected by security professional and just blaming the user.
- kjs3 7y agoHey, thanks for the condescension. You know what else our job as "security personel" (sic) is? Other than literacy, it's matching controls to risk. The guy who talked about "people dying" was a urologist; I can assure you the no one was going to die in his office because of passwords. So, yes, we should reduce friction where it's appropriate, but unless you understand the actual risk model, maybe you should keep your comments to yourself.
- matz1 7y ago"people dying" might be exaggerated but nonetheless because of the password he is inconvenienced. So you have to come up with different method. For the security personal, Dr is the customer, customer is king.
- txcwpalpha 7y agoThe doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored. It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doctor to keep in mind that the customer also requires that their data remain secure, and their ludditism should not interfere with that, either.
- kjs3 7y agoSaid much better than I could.
- ethbro 7y agoWhat happens if they forget their password?
- enriquto 7y ago> Curious, why would a doctor decline to use basic password auth? I'm not a (medical) doctor and I decline to use password authentication as well. Give me public key access or fuck off.