Live data from Hacker News

Comparing how security experts and non-experts stay safe online

googleonlinesecurity.blogspot.com

11–20 of 122 posts

Re: Comparing how security experts and non-experts stay safe online

#12

Do security experts place less emphasis on virus scans because they do their browsing on OS for which virus scanning is less important? EDIT This question is partly motivated by wondering if a Linux browsing user should be running a virus scanner?

Security experts have more faith in their ability to avoid triggering a scenario where a virus has the chance to gain a foothold. That's why there's such an emphasis on patches, to plug the holes they can't see to personally.

Re: Comparing how security experts and non-experts stay safe online

#14
A plug for our paper, also at the SOUPS conference. We tackled a similar topic, but with a different method and broader focus (how experts and non-experts in general conceptualize the internet as a system): https://www.usenix.org/system/files/conference/soups2015/sou...

It's great to see a large company like Google focusing on this kind of work though.

Re: Comparing how security experts and non-experts stay safe online

#15
post #9
post #8

Earlier quoted context omitted.

Can we settle for containers instead? For example, running Chrome in a Docker container. Why not? Drawbacks? Security risks? Feasibility? I understand that users download things but personally I can't recall doing that in recent memory, other than things like news/tech spec PDFs for later review. Moving downloaded files out of the browser's container would involve a fair bit of ceremony (physically selecting files/fo…

No. I'm barely on board with the pain/benefit of running an isolation VM. Containers provide so much less isolation than VMs, it's hard to imagine they're worth the inconvenience. (I hate VMs so much I just use two computers).

Why do you hate VM's so much? Usability? Or is there some technical reason?

Re: Comparing how security experts and non-experts stay safe online

#16
post #8
post #4

The thing that software security people do that most normal people don't do is: browsing and accessing email in a virtual machine, not their actual machine.

Can we settle for containers instead? For example, running Chrome in a Docker container. Why not? Drawbacks? Security risks? Feasibility? I understand that users download things but personally I can't recall doing that in recent memory, other than things like news/tech spec PDFs for later review. Moving downloaded files out of the browser's container would involve a fair bit of ceremony (physically selecting files/fo…

It's very easy (trivial even?) to browse in e.g. Virtual Box these days - why do the less secure thing?

Re: Comparing how security experts and non-experts stay safe online

#17
I am personally concerned with the "patch, patch, patch" message. Stated that way, I completely agree with it. However, for many it is just "update, update, update."

I'm all for getting the latest security patches. Or any security patches, really. I'm growing tired of getting the latest possibly risky feature from a product because it is the only way I can get a security patch.

Re: Comparing how security experts and non-experts stay safe online

#18
post #17

I am personally concerned with the "patch, patch, patch" message. Stated that way, I completely agree with it. However, for many it is just "update, update, update." I'm all for getting the latest security patches. Or any security patches, really. I'm growing tired of getting the latest possibly risky feature from a product because it is the only way I can get a security patch.

Twice daily "Adobe updates are available, please download and install!" - annoys me to no end

Re: Comparing how security experts and non-experts stay safe online

#20
post #17

I am personally concerned with the "patch, patch, patch" message. Stated that way, I completely agree with it. However, for many it is just "update, update, update." I'm all for getting the latest security patches. Or any security patches, really. I'm growing tired of getting the latest possibly risky feature from a product because it is the only way I can get a security patch.

This is what the average Linux distributions repositories are for.
Post reply on HN