9 ms·
As someone who worked as a pen-tester, security is almost ALWAYS at odds with convenience. Making better security less and less inconvenient is the name of the
by bszupnick 6y ago
As someone who worked as a pen-tester, security is almost ALWAYS at odds with convenience.
Making better security less and less inconvenient is the name of the game. Even if 100% security would be as easy as ticking a box, though, the fact of the matter is that most people don't care and if it's not "secure by default", it simply will stay not secure.
Maybe a synonym for "turned on by default" is "absolutely zero inconvenience or attention needed"
- happytoexplain 6y agoI'm a little baffled as to why this is getting downvoted. It seems so true and uncontroversial.
- naasking 6y agoIt seems true because people don't consider disasters, like the mortgage crisis, or this pandemic. Consider the magnitude of inconvenience from having your identity stolen. I think it dwarfs any minor inconvniences needed to secure your identity. That said, no doubt user-computer interaction should study security a little more I think.
- kube-system 6y ago> Consider the magnitude of inconvenience from having your identity stolen. I think it dwarfs any minor inconvniences needed to secure your identity. It's not as simple as a boolean situation, though. There's not any single set of security steps that a person can take to definitively 'secure their identity'. It's a gigantic continuum, where inconvenience asymptotically increases as you approach complete security. Everyone chooses some amount of risk which is less than complete security. The only real argument is over which point along the continuum is appropriate. There is no one correct answer, either.
- deleted 6y ago[deleted]
- JoeAltmaier 6y agoThat's a leap, from 'some security' to 'absolutely zero inconvenience'. There's no middle ground? Don't we all use passwords now for many things? That's not zero attention needed.
- happytoexplain 6y agoMy interpretation of the parent post was not that there is no middle ground, but that if a user can use a service without engaging in an extra step to increase security, they will do so, no matter how easy the extra step is. Passwords are not an extra step - they are required.
- JoeAltmaier 6y agoPasswords are optional for some things (spreadsheets, SSL keys) - would be interesting to get the actual stats on how often they get used.
- 0xff00ffee 6y agoPassword managers have turned this into near-zero inconvenience: when I arrive at the login page my UID and PW are already filled in. (I also have three hard tokens for from banks and investments, two ubikeys (both for LastPass, one in storage), and google authenticator on my iphone for anyone that offers it... so I've taken a step backward for added security.)
- JoeAltmaier 6y agoAll that took very much more than zero effort to set up. More evidence than people will put up with inconvenience for security.
- setr 6y agoI think for most people, they're trading less convenience (manually dealing with passwords, and the randomly changing rules and resets different places use) for more convenience (autofill, managed & synced) Which happens to also be more secure.
- jidiculous 6y agoHonestly, this makes me appreciate Signal all the more – it seems the only barrier is getting friends to adopt it, but if used by an organization could it be an alternative to E2EE email?
- tptacek 6y agoYes.
- NikolaeVarius 6y agoIn my experience, the client is stupidly buggy. I've lost messages silently multiple times. This is a known issue and after losing several key messages stopped using it. So, IMO the barrier is, "actually working" https://github.com/signalapp/Signal-Android/issues/5253 https://github.com/signalapp/Signal-Android/issues/5253 https://github.com/signalapp/Signal-Android/search?q=missing+messages&type=Issues https://github.com/signalapp/Signal-Android/search?q=missing...
- asdf-asdf-asdf 6y agoit probably should be mentioned that the first github issue you linked is about signal loosing SMS-messages, not signal-messages. so for the case mentioned by the parent (" getting friends to adopt it") it is not really relevant.
- Vinnl 6y agoOne thing I've been able to tell friends is to just replace their default SMS app with Signal, since they're not particularly attached to that app anyway. Then, at least their messages to me will then be encrypted, and every additional person I get to install Signal will have an additional contact being able to use it/join a group.
- strbean 6y agoI did that, but it was disappointing losing my message history for SMS messages when my phone boot-looped and I had to re-flash.
- ses1984 6y agoSecurity is convenient. Losing your sensitive data is pretty damn inconvenient.
- happytoexplain 6y agoThis is true, but not pragmatic.
- jerf 6y agoThere is a useful idea called Pareto Optimality: https://en.wikipedia.org/wiki/Pareto_efficiency https://en.wikipedia.org/wiki/Pareto_efficiency If you measure two things, you can draw the "frontier" between them, sketching out the max of X that you can have while having an amount of Y. This will draw a graph where the lower left is the part you can reach, and the the upper right is the part you can't, e.g. you can't have 100% security and 100% usability. When you are on that frontier, than the two things are in apparent opposition to each other, in the sense that you can't get more of one without having less of the other. However, if you are not on that frontier, then suddenly the conflict evaporates, because you can indeed have more of one without less of the other. (Almost everything we ever talk about as software engineers being in "opposition" to each other is actually in this relationship. Sometimes optimality on one axis is so easy to achieve that it's still practical to discuss the two things as being in "opposition", but most of the time, before worrying about to things being in opposition it should first be checked that we are indeed on this optimality frontier. Otherwise we risk constraining our thoughts into a win/lose frame and miss the win/win options on the table.) All of that is a lead up to my claim that the idea that GPG is on the Pareto frontier for usability and security doesn't pass the smell test. In fact it manages to have such a bad UI that it adversely impacts the security it can provide. It isn't just what git calls the "porcelain", either; some of the fundamental data structures GPG uses are just not quite right and produce fundamental confusion. It certainly doesn't help that the UI is so obscure that even a heavy user can be confused by everything that is going on. GPG really needs a total UI overhaul, but I think this is one of those cases where the existence of an apparently "blessed" product (the GPG distribution itself) prevents anything better from being able to get enough of a foothold to succeed. If you waved a magic wand and made me the PM over the GPG product, I'd be putting out a call to the community to make a better UI, no holds barred (i.e., fundamental data structure changes are on the table and while I wouldn't necessarily want to promise a lack of backwards compatibility, don't be afraid to break it), and in a year we'll circle back around to the proposals and the GPG project itself will bless one of them. But that probably won't happen. (And I personally lack the bandwidth and the gpg street cred, so "why don't you do it" isn't a terribly practical response.)
- hinkley 6y agoTurns out the Pareto frontier explains a big chunk of my thesis on performance vs readability.
- deleted 6y ago[deleted]
- sz4kerto 6y agoWe're developing an electronic health record platform that stores data encrypted in a way that we don't have the decryption key. We don't have end-to-end encryption, but if you got a database dump then it'd be quite tricky to decrypt what's in it as data belonging to a person can be unlocked with a secret that the person has, and we don't; only in memory when serving the user. So we're very far from perfect, but still better than most providers in this space. However, the fact that we can't easily do database migrations, debugging, etc makes our lives extremely hard, and it's much more difficult to compete in terms of UX.
- csours 6y ago> Making better security less and less inconvenient is the name of the game. Bingo. It's really easy to overlook UX, but it's the name of the game for actually improving things. Dev Experience too. There's a perverse problem in secure development, where you need to know enough to figure out why something is going wrong, but you must not leak information.
- jiggawatts 6y ago> security is almost ALWAYS at odds with convenience. I hate this attitude. Vehemently. It's borderline ethically irresponsible to say it out loud, because it gives muggles the notion that they can save costs by reducing security, which is often simply not true. Security is very often the cheaper option, or at least the smoother one. Certainly from an end-users' point of view, it's more convenient. Let me list some examples: Windows v1909 has a bunch of hardware-enfoced security turned on by default (=low admin effort), invisibly to the end user (=convenient). Older operating systems either have none of this, or it's a manual task to enable these optional features (=expensive). A good HR automation process means that when a new employee starts, they automatically gain access to whatever they need, and nothing they don't. This is great for the user, because "everything just works" and they have everything they need available (=convenient), but it's secure because there is no error-prone manual processes to grant them access to things (=cheaper). Windows 10 Hello for Business is essentially a virtual smart card stored in the TPM chip of your laptop, secured with a PIN or biometrics as a second factor. It uses modern cryptography and works transparently with Kerberos. It's as strong as a Smart Card but is more automatic than a password.(=convenient) It requires no hardware to deploy, and essentially eliminates a bunch of attack vectors (=cost neutral or even cheaper). Simply enabling WSUS or leaving Windows in automatic patch mode is literally the cheapest and most secure option, yet many organisations insist on spending tons of time, effort, and money on "managing" their patches. This inevitably results in totally unnecessary paper pushing, and no measurable benefit. Meanwhile, Microsoft releases protocol-breaking changes (such as the CredSSP thing recently) in waves, with the "enabling" patch one month, and then the "enforcing" patch the next month. Smooth as silk. Except for every. Single. One. Of my customers that insisted on "managing" their patches in quarterly rollouts or whatever that had a major outage because they skipped patches. You get the idea. There is a "happy" path of less effort, more convenience, yet very good security. Not perfect, but good enough. Conversely, this attitude of "we must reduce security to reduce costs or improve convenience" is just insane. I've seen people go out of their way to purposefully weaken the default security of a system because of this logic. So please. Even if you know better, just never, ever say anything like this out loud. The world is full of Muggles, and they hear this shit and do random stupid stuff that lets the Chinese government steal our hard work.
- pfundstein 6y agoCounterpoint: SSH, HTTPS, SMTPS, IMAPS, etc, all require no more interaction from the user than their insecure counterparts.
- recursive 6y agoCounterpoint: I work for a company that sells software to mostly big companies. Sometimes they want to host it themselves. Creating valid certificates usable for HTTPS is a never-ending support issue.
- couchand 6y agoYou should support ACME.
- johannes1234321 6y agoDoesn't help on the intranet that easily, when the application runs on a domain not on public DNS. Also ACME can be problematic from policy POV.
- couchand 6y agoMy working theory is that the Venn diagram of organizations self-hosting software on an intranet with private DNS and organizations that don't have an internal CA is almost entirely disjoint. Are the policy concerns you raise related to the above, or something else?
- de_watcher 6y agoYour diagram is wrong tho.
- recursive 6y agoSome of our customers have no trouble with certificates. The others have never heard of ACME.