Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This describes pretty exactly why security questions are hard.

It's not as easy as using tool x and generate key y... its more than using software, if you want security, you have to think about the whole stack, down to the access rights that each part of your hardware has.

There are good and best practices, but with IT Security, using the best practices in one place and just plain forgetting to unlock you PC when you go to the toilet at the office is more than enough...

People are allowed to be afraid when asked security questions.



> just plain forgetting to [lock] you PC when you go to the toilet

You're not even trying. Physical access, game over, the lock is irrelevant.

You fear what you don't understand, and you don't understand because you're afraid to learn. You have simply crafted a vicious cycle for yourself, and are making the world that much more unsafe by spreading your fear and acting as if everyone should share in your fear.


I'm not spreading fear, since i consider HN a place where people are educated enough understand the problems in it security.

Yes, once someone has hardware access, its devilishly hard to secure an environment, but just stating that its impossible is as wrong as security systems that ask their users too many questions to which they most likely have no good answer/no doubtfree answer.

There are systems which work pretty securely, i have worked with several educated security experts to create security infrastructures in companies.

I'm not saying that i don't understand the problems or don't want to learn solutions to them, i'm trying to defend the position of the user that can't be asked to learn about all the caveats of it security, since it is one of the most complex problems in computer science.

No, not every front-end developer that has to check-in his html und js files can be asked to understand all principles of it security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: