4 ms·
This article is from 2009. Most recent comment from 2010. Possibly, it is meant as a reminder of something that we should all not forget? Would the submitter
by Smushman 11y ago
This article is from 2009. Most recent comment from 2010.
Possibly, it is meant as a reminder of something that we should all not forget?
Would the submitter please take the time to clarify the reasoning for necroing this article?
- bargl 11y agoEven though this is the first time this article has been posted on HN. Security advice is so quickly outdated that this article very likely isn't relevant today. I don't know how prevelant some of the password management tools and two factor authentication was in 2009, but it's common to use them now. Browsers are more sophisticated and the landscape has changed a lot. That all said the sentiment of the article still stands true. Users (like my family) hate worrying about security.
- jerf 11y agoPeople who know what they're doing may have better security, but when I have to return to the "mundane world" nothing's changed. Passwords no greater than 8 characters... case insensitive with no symbols allowed with a mandatory number... getting mailed my password back in plain text when I use recovery mechanisms (or, well, my wife actually since my password management generally outlasts my accounts)... it's all still out there.
- bargl 11y agoI use my family as my baseline. It is a much easier sell to my family to use LastPass vs 16+ random characters (16 for MSDN). So as a whole I think now it's an issue of education. Yes I know LastPass is controversial, but it is still better then password1 or 1234.
- Karunamon 11y agoI'm not sure the advice or the conclusions are at all outdated... * Updates still suck, users still can't tell the difference between fake and real ones * Passwords are still annoying * 2FA exists, is better than 5 years ago, but most people don't use it because, and this is the articles point, it's still annoying * Recognizing phishing URLs can still be hard to do, even for tech savvy people * Cert errors are still false positives (in that there is no danger, not that there is a technical issue) more often than not
- deleted 11y ago[deleted]
- bargl 11y ago>* Updates still suck, users still can't tell the difference between fake and real ones Browsers now automatically update. There is the issue with adobe updates, but automatic updates make this different. Yes they still suck on many applications, but doesn't that affect the article? >* Passwords are still annoying LastPass, keePass and other tools give uses a much more simplified way to access our accounts. Also being able to link Google/Facebook to an account does the same thing. This article isn't 100% outdated, but it needs an update to address some of the changes that are there. What about HTTP vs HTTPS and signing in over starbucks? Does your average user know about that.? This is an issue of education and how to get the most bang for your buck, 2 factor authentication (easy), Password Management Software (easy), letting google/facebook/etc authenticate your account (easy). There are ways to make peoples lives easier AND more secure, I don't know if these tools existed back then but I've been using LastPass for 2 years and back then it was clunky to use. Now I personally find it easy as heck. I'm more secure (then I was) and my life is easier. To that end this article needs an update.
- monknomo 11y agoIf password management software was so easy, my mom would use it and my dad wouldn't call tech support every week to figure out how to use his. I'll say that it's better than it has been, but I can't call it easy.
- scott_s 11y agoIt is indeed still relevant, as it is not "security advice". Rather, it's advice to the security community on how to consider what advice they give to general users.
- bargl 11y agoPlease see my comment here https://news.ycombinator.com/item?id=9893126 https://news.ycombinator.com/item?id=9893126. I was talking about the referenced article Microsoft research paper when I said it was not relevant.
- scott_s 11y agoI was also talking about the paper by Cormac Herley from MSR. The lasting value of the paper is not the specific best practices that are not being applied. Those are examples of the claim people are being rational when they ignore security advice. The value in the paper is in the idea that users are acting rationally, and backing that up with some math and concrete examples.
- bargl 11y agoI should not have called the article irrelevant, but instead stated that it needs an update to include modern techniques, practices and risk factors. One of his examples in 7.3 User Effort is not Free he mentions the users time in input of a 6 digit pin vs an 8 digit password. But he doesn't include the use of a password management system. If you use a password managment system you can actually save time on password input. Then look at his section on passwords. The same thing applies. And the article is not security advice but it contains security advice from 2009 which is different today.
- zaphar 11y agoDid you read the article? It's not about security best practice. It's about human nature and how that relates to security best practice. Until human nature changes this article is going to be pretty close to timeless.
- bargl 11y agoSorry I wasn't clear in my comment, but at the end I state the same thing. The Schneier article is still true, but the linked microsoft research article needs an update. >That all said the sentiment of the article still stands true. Users (like my family) hate worrying about security. When I said "article" I was talking about the full document which gets directly into security best practice. http://research.microsoft.com/en-us/um/people/cormac/papers/2009/SoLongAndNoThanks.pdf http://research.microsoft.com/en-us/um/people/cormac/papers/... Also HN Comment guidlines indicate you shouldn't ask Did you read the article? > Please don't insinuate that someone hasn't read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- zaphar 11y agoYou are correct. I usually don't start out my comments that way. It was an off day. I'll leave it as is so your reply still makes sense :-(
- bargl 11y agoI was also having an off day yesterday specifically around HN, but seeing your comment made my day. Thanks :-) I hope you have a much better day today as well.
- teekert 11y agoDoes the fact that this article drifts up on the HN front page not inherently make the submission worth while? Or should all up-voters clarify their reasoning behind doing so? I mean, many people may have many reasons that got this article to the front page, does it really matter what they are (or what the single reason of the submitter was)?
- bargl 11y agoThe article definitely needs a (2009) on it. Who knows if it had that would it have drifted up? No point it speculating, but it does need the year tag.
- scott_s 11y agoOlder submissions should have a (YYYY) in the headline to indicate they're old, but posting older things is a common practice on HN. It just means, "Hey, I ran into this older thing that I think is still interesting, and I thought the community would too."
- Smushman 11y agoIndeed, it is definitely still relevant. I was attempting to ask for information that I intended/hoped to stimulate conversation. I also intended to highlight that the article was 2009; as I spent the time to read it and began a response before I observed the date.