Live data from Hacker News

Ceremonial security and cargo cults

philvenables.com

21–30 of 49 posts

Re: Ceremonial security and cargo cults

#21
post #9

My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…

> Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security.

I have to agree with you because I have seen first hand how many ordinary office workers, if left to their own devices and not given any other tool that they're mandated to use, will happily and blithely do things like store shared credentials/passwords in an Office365 Excel sheet that everyone in the company has access to.

It's the role of the infosec people to set up something better and work with the C-levels to ensure that its usage is mandated, and people are not sneakily bypassing its use or sharing credentials for expediency's sake.

Re: Ceremonial security and cargo cults

#22
post #14
post #6

Earlier quoted context omitted.

No offense, but I think you're exactly wrong. People need to trust the science, so to speak, and leave the thinking to domain experts who can dictate the best course of action for everyone. On their own, too many people are prone to following misinformation, and can't even be trusted to read both sides of any given argument critically. If the last few years hasn't taught us this lesson, what has it taught us?

It has taught us that media distorts scientific information on demand. I am generally on your side, however, my lesson in the last years is that the communication channels can not be trusted, therefore I can no longer blindly trust what science supposedly tells me.

Also scientists distort scientific information.

I was recently arguing with a vegan about how healthy it really is to be vegan, and I sent a german paper that tested 75 people and found a generic lack of iron absorption.

The other person said 75 is too small size, and sent me a literature review that claimed that iron absorption in vegans is fine. The only source for that claim in the literature review was the same paper I had originally sent.

So the authors of the literature review just quoted a paper, completely changed the original conclusions, and got it approved.

If we were serious about science, they should all face punishment for even attempting this. But they knew that at worst their paper would be rejected.

Re: Ceremonial security and cargo cults

#24
post #22
post #14

Earlier quoted context omitted.

It has taught us that media distorts scientific information on demand. I am generally on your side, however, my lesson in the last years is that the communication channels can not be trusted, therefore I can no longer blindly trust what science supposedly tells me.

Also scientists distort scientific information. I was recently arguing with a vegan about how healthy it really is to be vegan, and I sent a german paper that tested 75 people and found a generic lack of iron absorption. The other person said 75 is too small size, and sent me a literature review that claimed that iron absorption in vegans is fine. The only source for that claim in the literature review was the same p…

It is similar to what happens with teachers where I come from. Once you managed to obtain the status of "teacher", it is virtually impossible to loose it again, no matter how bad your teaching is. Apparently, something similar is going on with scientists, and a few other professions. There is no mechanism in place to get rid of bad apples, because society thinks it would be unfair to remove someone from a job where they had to go thru considerable training to actually get it.

Re: Ceremonial security and cargo cults

#25
post #7

This is an interesting article that puts words into what I've been feeling and observing for a long time — at first the transition into Academia from tech felt this way (e.g. wow everyone's programmed to follow the PhD track!) to moving to Australia (wow everyone's so rule abiding and pattern matching; anyone who's attempting to "lead" gets cut down; there's even a term here for it called "tall poppy syndrome) But la…

> But lately with all the layoffs it's kind of put a spotlight on tech startups and VCs. These are the smartest group of people who are supposed to escape mimetic behavior...

Well. That is your problem. You bought the marketing. There is no reason to think that VCs and startups are the “smartest group of people”.

Re: Ceremonial security and cargo cults

#26
post #9

My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…

I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives.

Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot IT person doesn't realize that we're at n*10^5 servers and still fails to understand how braindead his request is when you explain it to him.

A lot of people now persue the IT security industry itself without having any shred of experience managing computer systems, then confidently wade out into industry claiming to be experts.

Re: Ceremonial security and cargo cults

#27
post #6

I believe that such dogmatic "thinking" (if one can call it that) exists and propagates only because people are being discouraged from thinking critically. They are instead encouraged to find "best practices" and "solutions" from others (often giving them $$$), which they can blindly follow, instead of evaluating their unique circumstances and thinking independently about their own needs. The constant use of "securit…

No offense, but I think you're exactly wrong. People need to trust the science, so to speak, and leave the thinking to domain experts who can dictate the best course of action for everyone. On their own, too many people are prone to following misinformation, and can't even be trusted to read both sides of any given argument critically. If the last few years hasn't taught us this lesson, what has it taught us?

Should we have trusted the experts on satanic ritual abuse in the 80s and 90s?

I have many gripes with this attitude; experts can be wrong and even entire fields can be wrong. The satanic ritual abuse is a particularly egregious example with many "experts" mouthing off complete nonsense, but also see e.g. the replication crisis.

And which expert do you believe? There are many expert. "You've got to ask the right expert" https://www.youtube.com/watch?v=lADB9Qu53CY

Remember all the "experts" that told us that asbestos and smoking was harmless? Or the "experts" that told us climate change wasn't real? Later turned out that this was just industry FUD/lies.

Experts view things from their expertise. That's great, but many scenarios extend beyond one expertise and involve trade-offs, and can't be viewed purely through one lens.

Now, I'm not so arrogant to think that "I know better than the experts"; in many cases I don't, but to always just "believe the experts" seems naïve.

Re: Ceremonial security and cargo cults

#28
post #9

My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…

I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives. Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot…

The “proof via a series of tedious screenshots” method of audit is absolutely infuriating. Please bring on the 10x auditors…

Re: Ceremonial security and cargo cults

#29
post #12

I’ve found it immensely frustrating in numerous roles when discussing security, audit and compliance requests that the requesters can seldom actually explain their reasoning. I want a clear statement of risk and why their proposed compensating control actually mitigates it. Far too often the answers are just “it’s securerer” or “it’s the way we do it”, and actually proposing something that genuinely mitigates the und…

I aim to build systems that are both secure and compliant. It’s convenient when (but not a given that) those two adjectives overlap with each other.

Re: Ceremonial security and cargo cults

#30

Earlier quoted context omitted.

I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives. Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot…

The “proof via a series of tedious screenshots” method of audit is absolutely infuriating. Please bring on the 10x auditors…

Then they printed those screenshots out to be bound into a thick report to be presented the board. (Not where I am but in a previous employer. Still makes me laugh).
Post reply on HN