Ceremonial security and cargo cults
philvenables.com
Ceremonial security and cargo cults
1–10 of 49 posts
Re: Ceremonial security and cargo cults
#2Re: Ceremonial security and cargo cults
#3An essay without a thesis? The topic seems interesting, but I am not sure what the author wanted me to get out of this.
Re: Ceremonial security and cargo cults
#4Re: Ceremonial security and cargo cults
#5Re: Ceremonial security and cargo cults
#6I believe that such dogmatic "thinking" (if one can call it that) exists and propagates only because people are being discouraged from thinking critically. They are instead encouraged to find "best practices" and "solutions" from others (often giving them $$$), which they can blindly follow, instead of evaluating their unique circumstances and thinking independently about their own needs. The constant use of "securit…
On their own, too many people are prone to following misinformation, and can't even be trusted to read both sides of any given argument critically. If the last few years hasn't taught us this lesson, what has it taught us?
Re: Ceremonial security and cargo cults
#7But lately with all the layoffs it's kind of put a spotlight on tech startups and VCs. These are the smartest group of people who are supposed to escape mimetic behavior... but how do you explain all the VCs investing in me-too scooter companies or BNPL companies or yet-another-meal/grocery-delivery-service, who are now all absolutely wrecked by higher interest rates because these can only really thrive (or even survive) in low to no-interest rate environments? Why would these ever be $1B+ companies in the first place??
Sorry for the rant, it's just that the more you look, the more even the "smartest people in the room" are just performing rituals and it's disheartening and depressing.
Re: Ceremonial security and cargo cults
#8Re: Ceremonial security and cargo cults
#9Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security.
Compliance is an easy way to force everyone to three-quarter-ass, possibly even hit 90%. It's true that, without compliance, some orgs will hit 99%. It's true that some compliance requirements force you to be less secure than you might otherwise have chosen [1]
But it's also true that for every org that would hit 99% under their own steam, there are a hundred that would do the default ubuntu install, then only patch when something breaks. And that is why I like compliance. I work with our compliance team on lots of things, and everybody ends up winning.
[1] Consider password rules. Some compliance rule says must have a couple funny characters and a mixture of upper and lower case, minimum ten characters. Basically, forces a password that users hit the minimum on, then have no choice but to write down. Compare with an entropy-based measure that would lets users have an essay question, but one that's memorable and has higher entropy. Far more secure, yet rarely how compliance express their password concerns.
Re: Ceremonial security and cargo cults
#10A manager once asked me to rewrite a bunch of tests written by some former employee, because a security tool was complaining about hardcoded credentials. My guess is that he wanted to satisfy some OKR about how many security issues reported by that tool had been "fixed". Probably the most ridiculous thing I've done.