24 ms·
Your security is increasing at risk from organisations and corporations whose own grasp of security is appalling. Because instead of dealing with it they extern
by nonrandomstring 3y ago
Your security is increasing at risk from organisations and
corporations whose own grasp of security is appalling. Because instead
of dealing with it they externalise risks and consequences onto the
public and customers.
Even worse, is where attempts to query that security is actively
punished.
This is typical now. Listen here (at 42:20) with an example regarding
the UK NHS whose incompetence plays directly into the hands of
cybercriminals.
[0] https://cybershow.uk/episodes.php?id=24 https://cybershow.uk/episodes.php?id=24 (time:42:20)
- corndoge 3y agoSince the link to this podcast is in your profile, you're affiliated with it, right?
- nonrandomstring 3y agoYes
- em-bee 3y agoEven worse, is where attempts to query that security is actively punished. like this case: https://news.ycombinator.com/item?id=37250024 https://news.ycombinator.com/item?id=37250024
- nonrandomstring 3y agoExcellent example em-bee, thanks! I'm writing up a blog post on this subject, so more examples welcome plz.
- gpderetta 3y agoMy UK bank semi-regularly cold-calls me and ask me to authenticate by providing personal information. When I decline they readily tell me instead to call some number available on the bank website. So they not only are incompetent, they actually know it.
- em-bee 3y agowhy? isn't getting the number from the website the right action? you can verify that you have the bank website, get the right number, and i presume even go to the bank branch to get the number in person, and then save the number as it should not change. or are you referring to the call itself? i wonder why they need to do that.
- gpderetta 3y agoIt is the right action, and they should say exactly that when they call: we need to talk to you so call us at the number in our website. Instead they try to do the wrong unsafe thing, but when pointed out they switch the script. So they can't even claim ignorance of basic security .