4 ms·
I think this is really why we can't "have fun" anymore. Because bad actors exist and can exploit things being done "just for fun". I do wonder, however, how muc
by colonelpopcorn 5y ago
I think this is really why we can't "have fun" anymore. Because bad actors exist and can exploit things being done "just for fun". I do wonder, however, how much of the "serious" nature comes from actual bad actors or from the security research community.
- howdydoo 5y agoIt's more of a risk/reward thing. Any code on a networked computer has non-zero risk. And what's the reward... an engineer had fun at work today? That's not a very compelling argument in a business context. I say this as someone who snuck an easter egg into our product at my last job. Yes, it was fun, but if I had gotten in trouble for it, I would have deserved it.
- gumby 5y ago> I do wonder, however, how much of the "serious" nature comes from actual bad actors or from the security research community. I think it’s hard to think of the problem that way. These days* of course you have to worry about security on almost anything you work on. And when you do, the folks who think of security all the time are going to tell you to simplify your interfaces so they are easier to think about, then then armor them. What a pain! But we do those things because of all the bad actors. The security recommendations are a consequence, not the cause. * I grew up — literally — in a non-security environment: networked computers with no passwords or any other security. The only “protection” what would be called today kernel space memory barrier just to protect against bugs, and most machines didn’t have that. It was the late 70s and security was considered a barrier to hacking. I knew people working on security and frankly it seemed weird.
- SAI_Peregrinus 5y agoPhysical access to computers in the late 70s was decently secured. Most computers were at large businesses (typically with access through a lobby with a receptionist watching) or universities with access limited to students & faculty. So there was some security, not usually great, but few bad actors could get access, even across networks. As computers became more common physical-security-only stopped working well.
- gumby 5y agoIndeed. Mysteriously, “firewall” devices later became popular even though they merely replicated the weaknesses of physical security. Defense at depth is the only way to go, unfortunately.
- hpoe 5y agoCounterpoint. In our org we'd eliminate pretty much every security incident if users would not download attachments on suspicious emails, give out their password and try and click on the monkey to win the iPad. To quote James Mickens "most of the security reasearch community seems to be obssesed with avant-garde horrors such as the ability to induce a heart attack in those wearing pacemakers during a solar eclipse with a pringles can." At this point it seems that most of it really is just security theater and most really security actually comes from proper training.
- derekp7 5y agoIn my household back around Y2K era (95 - 05), I eliminated a large number of virus infections by having the computer that the kids used set up so them clicking on the AIM icon actually did an X connection over ssh to my Linux server to run GAIM (using Cygwin/X on the Windows side).
- gumby 5y agoThat quotation simply reflects what’s exciting enough to get attention. And of course there are the theatrical password rotation and such that cause passwords to be written down in the first place. But even in this comment stream someone asked who cares if the remote side learns the version number of the code you’re running, and somebody else wrote that security would not be a problem if users didn’t do what they considered foolish things. These pragmatic problems are where the risks lie.
- tomrod 5y agoMoTD and have fun all you want for people who should have access.
- Zababa 5y ago> I think this is really why we can't "have fun" anymore. Because bad actors exist and can exploit things being done "just for fun". That's often how things works. With friends we joke around a lot because we know each other well and know there aren't bad actors. At work, I'm way more careful. If there were no cases of harassement, exploitation or things like that at work I may joke around more. But since they exist, I'm more careful. I don't want to harass people, be seen as an harasser, or create an atmosphere were harassers feel welcomed. When bad actors exist, the way to show good will is to not act like them, so they can be quickly identified and removed.