Live data from Hacker News

Stop Hacklore – An Open Letter

hacklore.org

111–115 of 115 posts

Re: Stop Hacklore – An Open Letter

#111
post #71

Earlier quoted context omitted.

>Personally, i think the worst part about it is handling a low probability as something that's not gonne happen. Thats, especially in IT-Sec, one of the worst practices. If you are an online service provider, sure. Low probability means it's going to happen, especially as you scale with users. For a small business IT team? You can't keep a clean sheet, the strategy is to reduce the probabilities of an incident and re…

Well even tho i think at the end of your comment you went a bit out of the way, i get your point and i agree to a certain point. You cannot reduce the risks to 0 - that's a matter of fact and i would never claim you could. I tend to say its a question of cost/gain. If the cost the attacker has to pay (work/invest/...) is higher than the possible gain (data/funds/...) you are on a good track for your companies securit…

>Im btw not working for an ISP,

I can see why you would take "online service provider" to mean an ISP, but I meant it to include SaaS and apps like whatsapp, google, etc.. as well

>Therefor the next time you argue that some security measure is just an CISO that doesn't really care about its users

Oh I didn't mean to imply that, there's no doubt that IT admins that overimplement security policies care in general, the critique is not about motives, rather the efficiency. I don't argue that they don't care or even that they are wildly inefficient, just that they are suboptimal on this specific point by going overboard.

Re: Stop Hacklore – An Open Letter

#112
post #35

Earlier quoted context omitted.

The article doesn't claim that things like O.MG don't exist, just that they're not a serious threat to modern devices. It's explicit on that point.

Well i just listed the O.MG cable to show that there are alot of people not knowing that such things exist. My point is that of : people should be better informed about what vectors of attacks exist. So mentioning the cable (in relation to a coworker coming to my desk and asking about it) was just an example of how informed average Joe/Jane are and that i think this is the more important part - educate the public not…

The piece isn't about getting people not to worry, it's about not wasting the worry on things that aren't real threats. People have limited space in their brains for things to worry about.

Re: Stop Hacklore – An Open Letter

#113
post #88

Earlier quoted context omitted.

Almost all CVEs are basically irrelevant to everyone that doesn't have some obligation to keep on top of patching them. Meanwhile, auto-updates are RCE by default.

Indeed. I'm far more worried about picking up a supply-chain hack via updates than I am that some low-profile denial-of-service attack will actually affect me; the updates themselves historically have caused me far more actual denials of service than they fix.

Case in point: “[Print] To meet security goals and support new print capabilities, this update transitions Windows printing components from MSVCRT to a modern Universal C Runtime Library.

As a result of this change, print clients running versions of Windows prior to Windows 10, version 2004 and Windows Server, version 2004 (Build number 19041) will intentionally fail to print to remote print servers running Windows 11, versions 24H2 or 25H2, and Windows Server 2025, that have installed this update, or later updates. Attempting to print from an unsupported print client to an updated print server will fail with one of the following errors: […]”

Re: Stop Hacklore – An Open Letter

#114
What Bob and the signatories fail to recognise is that they're attempting to swap out nuanced advice for foundational advice and they're patting themselves on the back for it, actually. that foundational advice has always been

the nuanced advice is for unsolved problems, so ... if you ask a nuanced question, you'll be ... directed back to foundational security advice ?

I don't think they've thought about it, perhaps Signatories shouldn't play risk-advice cosplay at population levels.

I'd be annoyed if this influenced policy because of who they are and not how dumb the logic is.

Re: Stop Hacklore – An Open Letter

#115
post #94
post #66

Earlier quoted context omitted.

BTW, I really would like to have a way to partially clear cookies – i.e., I don't want to be signed out of gmail, and maybe not out of the Mechanic's Bank of Alaska or Amazon or Netflix, but most other things could go. I don't think this is easy in Chrome, Safari or other mainstream browsers, is it? Yesyes, I do know that Big Ad can mostly stitch together some proxy profile of me anyway, but it would be more blurry.

Just use a separate browser profile for your critical accounts.

Doesn’t this leak info when clicking on a link in say gmail opening that link in another profile? Most URL’s have pretty long extra strings in them that I assume are just cookie-equivalent?
Post reply on HN