4 ms·
Well if you are a somewhat serious company you probably have a clean-desk policy, workstations that lock themselves after a couple of minutes inactivity and enc
by Puts 5y ago
Well if you are a somewhat serious company you probably have a clean-desk policy, workstations that lock themselves after a couple of minutes inactivity and encrypted hard-drives. Also there are probably areas where you don't let the cleaner go, like that closet with all the switches. And the cleaner has in some form been vetted. You see that person a couple of days every week and start building a relationship. You can see if he/she suddenly shows up drunk every day.
With security and risk it works like this. You can accept some risk if you at the same time find solutions to mitigate any dire consequences. With third-party javascripts you are giving away all control. Now if you are in an nonsensitive business maybe it's okay to use some third-party javascripts here and there, but is it reasonable to have those on an e-commerce checkout for example? Also Subresource Integrity has been mentioned a couple of times already here to mitigate the risks of third-party javascripts.
- bsder 5y ago> And the cleaner has in some form been vetted. Oh, you sweet summer child, I admire your optimistic view of life. Please never lose it. I have this facepalm discussion with people who want to "upgrade" our security by moving something into the office. "So, you want to trust our cleaning staff who regularly fail to lock our front door more than having it in a locked colocation cage with monitoring?" Even if the cleaning staff were "vetted" (which they are not), humans gonna human.