3 ms·
> almost every InfoSec stance out there Except other national bodies like NCSC [1], and long-standing academic research e.g. [2, 3], that is! 1. https://www.n
by kelnage 5y ago
> almost every InfoSec stance out there
Except other national bodies like NCSC [1], and long-standing academic research e.g. [2, 3], that is!
1. https://www.ncsc.gov.uk/collection/passwords/updating-your-approach https://www.ncsc.gov.uk/collection/passwords/updating-your-a...
2. https://dl.acm.org/doi/abs/10.1145/1866307.1866328 https://dl.acm.org/doi/abs/10.1145/1866307.1866328
3. https://link.springer.com/article/10.1007/s10623-015-0071-9 https://link.springer.com/article/10.1007/s10623-015-0071-9
- e1g 5y agoIn practice, when dealing with US auditors and infosec chiefs, saying that "Some researches/guidelines say X is not necessary" will not compel anyone to change because "This is always been this way, and it doesn't _hurt_". The conversation becomes categorically different if you say "The White House says X is not allowed anywhere."