> It matters that you don't seem to understand the threat model here.
Respectfully, a fairly common real world circumstance under which this is exactly the wrong choice was described, then ignored.
In response we got "you don't get it, we're staying where we are."
Is it possible that the reason people think you're doing the wrong thing is that you have made literally no attempt whatsoever to explain why you're flying against the best practices everyone else uses?
Saying "we have data" doesn't count, because we didn't see it, and everyone says that while justifying obviously incorrect stuff. I've had people mail my password back to me plaintext then insist that because they're (random important sounding thing) I should just trust their judgment.
And yes, this includes directors of security at first class software organizations with backgrounds in research security and the CIA.
Even if it turned out that you were correct, your current standoffish non-explanation is directly and severely undermining our trust in you. Do you just not care?
Sometimes you're a lot better off explaining than saying "you're too naive to understand."
.
> I've enumerated this multiple times now
Where?
.
> so I'm not sure how else to explain it
You give the very strong impression that you believe that saying "you're an amateur and we have data" is a kind of an explanation.
.
> The simple fact is that you need to lock your user account
"The simple fact is that you need to secure your server, and if you don't do that it doesn't matter that you salt and hash your passwords, and if you do do that then you don't need to salt and hash your passwords."
Yes, that's cute, LinkedIn. Back here in the real world, multiple layers of redundant, superficially weak, superficially unnecessary security have actual productive results.
.
> nothing else really matters because it's all just theater
The only theater I see here is "I've enumerated this and I don't know how else to explain it."
Unless you're talking about some other site, you haven't explained it at all, and what you're really saying is "I don't know how to explain it."
Maybe hire a communications person. You're making what appear to be by all basic security books and protocols dire security errors, then saying "I have data to support this decision and you're too dumb to understand what's going on."
Really?
Try us, sir. Closing the door in our faces is not a form of doing a good job here. If you're going to take liberties with our data, please be willing to give at least one good faith attempt to explain yourself. It's not a lot to ask.
.
> won't actually stop anyone willing to invest minimal effort.
I think you've confused wanting to stop blackhats with wanting to stop real world situations.
An angry significant other can pull this off. You're not just opening the door; you're opening it ridiculously wide, to the point that the average non-technical user can figure out how to penetrate your "security."
And then you're justifying it in terms of not wanting, through an unknown mechanism, to justify bad behavior, by leaving a vulnerability few technical people know about in place.
I just don't know how to respond to this.
Please share the data you keep talking about. The reason you don't know how to explain this better is that you haven't even begun to try.
Saying "I'm right and you're an outsider" isn't an explanation. It's a dodge.