Earlier quoted context omitted.
> It's not actually the extreme punishments, it's the consistent small punishments. Not just the consistent small punishments, but the painful punishments. Pain is an extremely good, human motivator. Why destroy someones life and spend valuable taxpayer money with a 10 year imprisonment, when a rigorous caning session will be 10x more effective ? Many criminals will loudly thump their chest if punishment is merely ja…
I guess Singapore doesn't have a lot of masochists?
We installed a single turnstile to feel secure
171–180 of 203 posts
Re: We installed a single turnstile to feel secure
#172Earlier quoted context omitted.
A third party script that's embedded into the task management website? Otherwise I don't see how it's going to get to the cookie. And if it is embedded into the website, it can force a fresh login and steal the cookie that way. And you can set HttpOnly to stop javascript from being able to access the cookie... but that still won't stop the attack of making them log in again.
The threat model I imagined here was: 1. Initial access to physical machine, most likely via phishing malware, reckless employees downloading untrusted content, or bad luck. 2. Malware looks for browser cookies, hoping to steal temporary credentials but instead gains persistent creds, which grant Jira access. People re-use passwords; malware tries this password against AdUser and any other systems or other corp user…
Re: We installed a single turnstile to feel secure
#173Earlier quoted context omitted.
The failings of the broken windows theory[1] would strongly disagree. [1]: https://en.wikipedia.org/wiki/Broken_windows_theory?wprov=sf...
So what are the failings? A quick skim through the Wikipedia article found plenty of criticism , but all the evidence I could find in my quick skim was in support of the theory. It's very likely I missed something in my skim; could you point to a specific section of the article where the evidence against the theory is presented?
Re: We installed a single turnstile to feel secure
#174Earlier quoted context omitted.
>I don’t know what exactly it was, but Singapore felt incredibly safe and crime-free. The extreme punishments for breaking the law might have something to do with it.
It's not actually the extreme punishments, it's the consistent small punishments. It's that you'll actually, seriously get a ticket for littering, even if it's a relatively small ticket. The "Fine City" enforces it's vision in a ubiquitous way, so people just don't break the rules.
There is another side to this, which is that the police need to not hassle people who are not committing crime. Which is why you'd struggle to adopt this anywhere in America.
Re: We installed a single turnstile to feel secure
#175I worked at a company that had effectively no physical security during work hours until the second time someone came in during lunch and stole an armload of laptops. Then we got card readers and a staffed front desk, and discovered our snack budget was too high because people from other companies on other floors were coming to ours for snacks too. I never felt the office was insecure, except in retrospect once it was…
I once lived in Singapore for a while and we were all sure that nobody would steal anything anyway, so we just never bothered to lock the doors. (That was also very helpful if you wanted to stop for a quick coffee with a date in the middle of the night.) You could see the MacBooks from the street, but nothing ever went missing. I don’t know what exactly it was, but Singapore felt incredibly safe and crime-free.
Re: We installed a single turnstile to feel secure
#176Earlier quoted context omitted.
A third party script that's embedded into the task management website? Otherwise I don't see how it's going to get to the cookie. And if it is embedded into the website, it can force a fresh login and steal the cookie that way. And you can set HttpOnly to stop javascript from being able to access the cookie... but that still won't stop the attack of making them log in again.
The threat model I imagined here was: 1. Initial access to physical machine, most likely via phishing malware, reckless employees downloading untrusted content, or bad luck. 2. Malware looks for browser cookies, hoping to steal temporary credentials but instead gains persistent creds, which grant Jira access. People re-use passwords; malware tries this password against AdUser and any other systems or other corp user…
1. Get e-mail from boss, look at headers, find boss IP addy
2. Failing that, memorize boss office number or workstation tag, run stealthy network scan, do reverse dns lookup
3. Be a router, arp spoof mitm attack
4. ?????
5. Profit
Re: We installed a single turnstile to feel secure
#177Earlier quoted context omitted.
It's not actually the extreme punishments, it's the consistent small punishments. It's that you'll actually, seriously get a ticket for littering, even if it's a relatively small ticket. The "Fine City" enforces it's vision in a ubiquitous way, so people just don't break the rules.
This seems like the most effective solution. Imagine if you knew that if you littered, there is a 100% chance you would get a $10 fine immediately. Almost no one would litter ever again, even though the fine is much smaller than the fine is in most countries. Problem is it just takes a lot of resources to police, more than the fine revenue. But with CCTV and computer vision it's getting increasingly cheap.
Re: We installed a single turnstile to feel secure
#178Earlier quoted context omitted.
Don't people feel anxious all the time? I do when I visit certain places like Singapore, where any misstep feels illegal.
Don't litter, don't do drugs, don't chew gum, don't drink in public after 10:30pm, and only smoke in designated areas. It really isn't that difficult.
Surely the entirety of the law is encapsulated in your comment. Certainly you won't get in trouble for carrying something as innocuous as an empty vape cartridge. You won't get fined for crossing the road in the wrong place, absolutely.
Singapore is just an example. Its more invasive big brother can be found just north of it.
Re: We installed a single turnstile to feel secure
#179I worked at a company that had effectively no physical security during work hours until the second time someone came in during lunch and stole an armload of laptops. Then we got card readers and a staffed front desk, and discovered our snack budget was too high because people from other companies on other floors were coming to ours for snacks too. I never felt the office was insecure, except in retrospect once it was…
She thought that because he was wearing a suit and a badge from his "company" that he must have been supposed to be there, and assumed he was probably taking the computers away to be fixed.
There was surprisingly little repercussion for violating the "one card one person" door policy and by someone whose job it was to know which visitors would be on-site on any given day, and so should have known that this guy wasn't supposed to be there.
Re: We installed a single turnstile to feel secure
#180Earlier quoted context omitted.
I once lived in Singapore for a while and we were all sure that nobody would steal anything anyway, so we just never bothered to lock the doors. (That was also very helpful if you wanted to stop for a quick coffee with a date in the middle of the night.) You could see the MacBooks from the street, but nothing ever went missing. I don’t know what exactly it was, but Singapore felt incredibly safe and crime-free.
>I don’t know what exactly it was, but Singapore felt incredibly safe and crime-free. The extreme punishments for breaking the law might have something to do with it.