Live data from Hacker News

Our Approach to Employee Security Training

pagerduty.com

1–10 of 76 posts

Re: Our Approach to Employee Security Training

#3
> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”.

Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic lists" when they want to read more about rainbow tables. Let alone the completely mad communication you'll get with people in the company.

> We implemented magic sodium suffix in our application this week, attackers won't be able to use magic lists when our magic data leaks.

>> What?

> You know, irreversible magic?

>> ...

Re: Our Approach to Employee Security Training

#4
> 2. Don’t shy away from technical details.

> The mere mention of the word “hashing” is probably enough to make non-technical employees’ eyes gloss over. So instead I just call it “Magic”.

What..? Why state a principle and then tell us how you violate it a few sentences later.

Re: Our Approach to Employee Security Training

#5
post #4

> 2. Don’t shy away from technical details. > The mere mention of the word “hashing” is probably enough to make non-technical employees’ eyes gloss over. So instead I just call it “Magic”. What..? Why state a principle and then tell us how you violate it a few sentences later.

[deleted]

Re: Our Approach to Employee Security Training

#8
post #3

> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”. Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic li…

How many non-engineers would you expect to take the interest/time to investigate rainbow tables after this? Also, if you follow the link to the actual presentation (https://sudo.pagerduty.com/for_everyone/#hashing for the lazy) then you'll see the author DOES indeed call it hashing, before switching to "magic" so as to make it easier for individuals without a technical background to not have to constantly think about what the term means.

Also, if you continue to RTFA,

> That said, I didn’t want to mislead people. So we chose to be clear to them that there is a technical term; it’s just not going to be important for the rest of the content.

If it's someone job to provide reports/updates on something related to the concept, yes they should know it, for anyone else in a non-technical role, why does it really matter?

Re: Our Approach to Employee Security Training

#10
Very interesting read, can't emphasise enough how important _practicing_ for security is as opposed to mere education. A couple of folks I went to Uni with launched a startup that helps companies conduct automated phishing awareness training and continuous employee sensibilisation by sending "white-hat" phishing emails: IT-Seal https://www.it-seal.de/en.html

I can highly recommend giving it a try. The first few levels of difficulty are easy to spot, but it's been eye opening for me how sophisticated phishing emails can get.

Post reply on HN