4 ms·
Of course you despise it. Security always comes at the cost of convenience.
by k8sToGo 3y ago
Of course you despise it. Security always comes at the cost of convenience.
- Cupprum 3y agoSecurity is inconvenience, therefore the role of security is to find where is the limit. Because afterwards users will start to search for shortcuts, which usually makes the systems even less secure.
- stevage 3y agoI don't despise all inconvenient things. I don't mind carrying house keys. It's just a question of whether you value the security enough to make it worthwhile.
- NoZebra120vClip 3y ago> I don't mind carrying house keys. House keys are a minimal inconvenience because the lock on your front door also affords minimal security. Just ask the Lock Picking Lawyer how long it would take a determined intruder to get into your home, whether by picking, force, or finding a weakness such as open window. If your home had high security, I can guarantee that you'd feel the inconvenience.
- pclmulqdq 3y agoYou can have a very secure facility that only uses a "house key"-style entry flow for the user. The key will look really weird (see Medeco and Evva for examples) and the building will have some design compromises - few entry points, no openable windows, etc. A password, in theory, could work the same way. Except that the normal password UX involves people remembering the password, which entails a huge security compromise.
- NoZebra120vClip 3y ago> no openable windows Yep, I'd call that a significant inconvenience (for a home that someone like me lives in).
- stevage 3y agoPersonally I'd be fine with password restrictions like 16 characters minimum etc etc. Still better than MFA.
- stevage 3y agoIndeed. But hopefully that was the tradeoff I had chosen. MFA irritates me because usually it isn't my choice.
- NoZebra120vClip 3y agoMFA has some sort of calculated irritation built into it. Part of it consists in the incredibly varied ways it can manifest. I could receive an SMS code, an email code, I could generate a TOTP code (choice of two Yubikeys), I could use U2F/FIDO (choice of 3 Yubikeys), I could get a Magic Link, I could use Sign in with Google, I could punt and use a code on my emergency backup paper. Don't forget to pass a CAPTCHA, and your password probably expired while you were away, as well. Of course this all transpires after I've unlocked my password manager's vault, which has its own style of 2FA security, its own timeouts, and its own UI/UX quirks. So you can see the sheer dizzying possible mutations of the MFA flow. Sometimes you don't even know what they'll hit you with until you try to log in! What amuses me is "We sent a code to your email. This message will self-destruct in 10 minutes." when email used to arrive on the scale of 5-7 days if the server was overloaded or busy. Oftentimes I find myself racing multiple timeouts to run the gauntlet of MFA in whatever way has been mandated.
- Mordisquitos 3y agoThose who would give up essential Security, to purchase a little temporary Convenience, deserve neither Security nor Convenience. — Frankmin Benjalin
- api 3y agoLol. That’s 99.9% of all users especially if you consider privacy a subset of security.
- CaptainFever 3y agoSecurity with the cost of convenience comes with the cost of security.