2 ms·
Counterpoint. In our org we'd eliminate pretty much every security incident if users would not download attachments on suspicious emails, give out their passwor
by hpoe 5y ago
Counterpoint. In our org we'd eliminate pretty much every security incident if users would not download attachments on suspicious emails, give out their password and try and click on the monkey to win the iPad.
To quote James Mickens "most of the security reasearch community seems to be obssesed with avant-garde horrors such as the ability to induce a heart attack in those wearing pacemakers during a solar eclipse with a pringles can."
At this point it seems that most of it really is just security theater and most really security actually comes from proper training.
- derekp7 5y agoIn my household back around Y2K era (95 - 05), I eliminated a large number of virus infections by having the computer that the kids used set up so them clicking on the AIM icon actually did an X connection over ssh to my Linux server to run GAIM (using Cygwin/X on the Windows side).
- gumby 5y agoThat quotation simply reflects what’s exciting enough to get attention. And of course there are the theatrical password rotation and such that cause passwords to be written down in the first place. But even in this comment stream someone asked who cares if the remote side learns the version number of the code you’re running, and somebody else wrote that security would not be a problem if users didn’t do what they considered foolish things. These pragmatic problems are where the risks lie.