Live data from Hacker News

Our Approach to Employee Security Training

pagerduty.com

11–20 of 76 posts

Re: Our Approach to Employee Security Training

#11
post #3

> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”. Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic li…

How many non-engineers would you expect to take the interest/time to investigate rainbow tables after this? Also, if you follow the link to the actual presentation ( https://sudo.pagerduty.com/for_everyone/#hashing for the lazy) then you'll see the author DOES indeed call it hashing, before switching to "magic" so as to make it easier for individuals without a technical background to not have to constantly think abou…

> Also, if you continue to RTFA,

I RTFpresentations even. Naming Hashing and then switching to Magic is just confusing for everyone involved. Again; it completely ruins effective communication.

> for anyone else in a non-technical role, why does it really matter?

They're getting security training on the topic of hashing. How does it not matter?? Employees will have to adjust their communication to toddler level anytime they need to talk about security to others.

Re: Our Approach to Employee Security Training

#12

If they can't understand hashing then there's no hope of teaching them security so why even bother?

No, if they can’t understand hashing, then you’ve failed as a teacher.

What Rich has done amazingly well here is use the correct term, but then made the “magic” analogy that allows the concept to be more easily understood by people not within engineering. Think sales, marketing, HR, biz dev, etc.

For those who are interested, they can look up more about hashing afterwards. But for everyone, the concept of how hashes are used was taught with high retention rates.

Re: Our Approach to Employee Security Training

#13
post #3

> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”. Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic li…

I think you totally miss the point. Explaining something by analogy can be the most effective way of "getting it". Everyone is different. You definitely cannot make such a bold statement about whether the approach was valid.

Re: Our Approach to Employee Security Training

#14
post #11

Earlier quoted context omitted.

How many non-engineers would you expect to take the interest/time to investigate rainbow tables after this? Also, if you follow the link to the actual presentation ( https://sudo.pagerduty.com/for_everyone/#hashing for the lazy) then you'll see the author DOES indeed call it hashing, before switching to "magic" so as to make it easier for individuals without a technical background to not have to constantly think abou…

> Also, if you continue to RTFA, I RTFpresentations even. Naming Hashing and then switching to Magic is just confusing for everyone involved. Again; it completely ruins effective communication. > for anyone else in a non-technical role, why does it really matter? They're getting security training on the topic of hashing. How does it not matter?? Employees will have to adjust their communication to toddler level anyti…

> They're getting security training on the topic of hashing. How does it not matter??

They're getting taught good password health. You don't need to know what hashing is to know good password health.

I shouldn't get upset over comments but it's headdeskingly frustrating to read comments like yours from people who should know better and who, ultimately, contribute to worse personal security for everybody. Comments like yours are one of the causes behind many people turning their head away at security, not bothering because the barrier of entry is too high and they're made to feel like if they don't have it perfect why bother.

Damn it. The guy communicated pretty damn well if he got 30 employees switching to password managers on their own without actually saying it's required. So instead of criticizing, take it as an opportunity to learn and revise your beliefs.

Re: Our Approach to Employee Security Training

#15
post #3

> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”. Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic li…

Devising a new, more familiar name for something like hashing is a good idea here because it communicates that “this is a complex thing handled by specialists, but it’s implications are important to us.”

Re: Our Approach to Employee Security Training

#16
post #4

> 2. Don’t shy away from technical details. > The mere mention of the word “hashing” is probably enough to make non-technical employees’ eyes gloss over. So instead I just call it “Magic”. What..? Why state a principle and then tell us how you violate it a few sentences later.

To be fair, they did say it was "our approach", they did not say it was a "good approach."

Re: Our Approach to Employee Security Training

#17
post #12

If they can't understand hashing then there's no hope of teaching them security so why even bother?

No, if they can’t understand hashing, then you’ve failed as a teacher. What Rich has done amazingly well here is use the correct term, but then made the “magic” analogy that allows the concept to be more easily understood by people not within engineering. Think sales, marketing, HR, biz dev, etc. For those who are interested, they can look up more about hashing afterwards. But for everyone, the concept of how hashes…

How is it even a good analogy? Hashing literally means chopping something up and making a mess. Heard of a hash brown? Hash is a dictionary word coming from French. You chop something up into a mess that you can't reassemble, but you get the same mess each time. The word magic needs to stay the hell away from computers.

Re: Our Approach to Employee Security Training

#18
post #4

> 2. Don’t shy away from technical details. > The mere mention of the word “hashing” is probably enough to make non-technical employees’ eyes gloss over. So instead I just call it “Magic”. What..? Why state a principle and then tell us how you violate it a few sentences later.

I think the point is that technical terminology and technical details are different things, and the latter is much more important.

The alternative is to say "hashing is a technical topic, and technical terms intimidate and confuse people, so we won't mention hashing". Instead, the article says that you should try to make hashing approachable and non-intimidating, since understanding the ideas around hashing will help people understand why strong passwords and password managers are important.

Re: Our Approach to Employee Security Training

#19
post #3

> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”. Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic li…

Concepts can have more than one name. An important part of preparing a training or presentation is understanding your audience, and using names that resonate with them.

If this had been a freshman college crypto class, the word "oracle" (https://security.stackexchange.com/questions/10617/what-is-a...) may have been used instead, to indicate that the exact details of hash reversing can be abstracted away and that the key detail is that it's much faster than brute force would suggest.

Re: Our Approach to Employee Security Training

#20
post #3

> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”. Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic li…

Devising a new, more familiar name for something like hashing is a good idea here because it communicates that “this is a complex thing handled by specialists, but it’s implications are important to us.”

[deleted]
Post reply on HN