Live data from Hacker News

Infosec's Jerk Problem (2013)

adversari.es

1–10 of 142 posts

Re: Infosec's Jerk Problem (2013)

#5
I read the first lines and thought immediately of all those e-mails marked IMPORTANT coming from "my bank" that request I immediately enter my username and password somewhere for "security".

Teaching blind compliance with any (unauthenticated) request based on "security" is the one way we could make the situation even worse.

Re: Infosec's Jerk Problem (2013)

#8

I read the first lines and thought immediately of all those e-mails marked IMPORTANT coming from "my bank" that request I immediately enter my username and password somewhere for "security". Teaching blind compliance with any (unauthenticated) request based on "security" is the one way we could make the situation even worse.

It's a pretty big deal. When everything starts at urgent and gets worse from there, people will just rescale the noise to be more understandable. It's just like the joke about sitting down and assigning points to a task and finding out everything is 100 or all bugs are critical or all tasks are top priority.

The meta joke here is that is some ways every security issue is critical, but if everyone is immune to the fear then escalation will feel like the only choice. Either you slowly discharge that stress immunity by being sensibly mellow, or you start packing heat to 'convince' everyone to reboot NOW. (There's probably room for some amount of finesse between these two extremes.)

EDIT: There's two terrible responses that seem to come out of this. Either no one gives a damn, or no one gives a damn and just does whatever you say. The first is bad because nothing gets fixed, and the second is bad for `red_admiral's reasons (users treat anything that looks like a security rant as a EULA and just do whatever it says).

Re: Infosec's Jerk Problem (2013)

#9
The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches.

> Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make the first move, you’ll be waiting a while — but extend a hand to someone who expects a kick in the teeth and watch as you gain a new friend. Smile.

I really like this quote. A security engineer and a developer teaming up together as colleagues, are more likely to being taken seriously by stakeholders. Both teams working together have a much better chance of being given the time needed to make sure their software is stable and secure.

Re: Infosec's Jerk Problem (2013)

#10

The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…

I would like to add that while this advice would generally work, there are some really shady characters that one has to deal with sometimes. In that case, the other person might just keep taking advantage of your kindness. So, there does have to be a give and take: do a little bit, and hope that they do a little bit as well.
Post reply on HN