3 ms·
Security engineers are basically expected to know everything. It's part of why I enjoy the work. But it's also impossible. "Understand the security implications
by staticassertion 4y ago
Security engineers are basically expected to know everything. It's part of why I enjoy the work. But it's also impossible. "Understand the security implications of every nuanced technology decision" is not tractable, so we pick the ones we can and specialize.
POTS is rarely of interest to a security organization. You have very few levers to pull even if you do consider it a threat, since it's just fundamentally an awful system, and you can't tell people "don't use telephones". At best you can train people, but your concern is probably phishing via email.
Only a few people, at the company level, are at risk in terms of this sort of attack, compared to everyone being at risk (with regards to the company) from phishing emails.
So a lot of people just don't really think about it. Security engineers might hand wavingly say "phone numbers can be spoofed" but I'd bet the percentage of seceng that know how that works is very small.