Live data from Hacker News

65% of employees bypass cybersecurity measures, new study finds

forbes.com

71–80 of 97 posts

Re: 65% of employees bypass cybersecurity measures, new study finds

#71
post #45
post #7

> Password Reuse: 49% of respondents use the same login credentials for multiple work applications, and 36% use the same credentials for personal and professional accounts. If your company has multiple things you need to log in to, its doing something wrong. Having company-wide single login system is really critical for good security. > 30% of employees share their workplace passwords with colleagues, effectively nul…

> If your company has multiple things you need to log in to, its doing something wrong. Having company-wide single login system is really critical for good security. It absolutely is, but it is only applicable to large corporations and won’t help any SMBs. The issue is that this functionality via LDAP/SAML/OODS is frequently locked behind enterprise subscription tiers that usually represent an extremely high markup o…

FreeIPA and Authentik works pretty well for me, I did some of this for my self with terraform for fun. Personally I don’t think it’s viable SMB who can’t hire a couple of sysadmins.

But the documentation for FreeIPA is especially good. Personally wouldn’t use samba as windows DC, but one legacy windows server license seems reasonable if you are having a few hundreds of employees.

In a previous job we’ve done Windows DC + Azure AD + FreeIPA + FreeRadius just fine, the entire setup is not super complicated, but still a headache. I think nowadays most of the thing can be terraformed so it could be easier and more scalable for growing SMBs.

Re: 65% of employees bypass cybersecurity measures, new study finds

#72
post #31

Earlier quoted context omitted.

Maybe if you work at a unitary company with a narrow scope of work. If you have to login to external systems belonging to other organizations, or have terminals for external systems in your facility, unitary identity is not an option.

Having a centrally administered password manager is usually an option, unless there are regulatory reasons not to.

I can't get a few of my clients to adopt password managers and they get logged out of their accounts constantly because an employee will change some password to an account the business depends on. These people want to suffer and roll around in fetid filth.

Re: 65% of employees bypass cybersecurity measures, new study finds

#73

AviD's Rule of Usability: "Security at the expense of usability, comes at the expense of security." Security companies should have more focus on the usability aspect of their product. Some of the enterprise products you see today are just plain bad in terms of UX/UI, and funnily enough, they aren't getting called out since they're only used in the workplace/closed groups.

Yeah there's a certain amount of effort most people are willing to put in to do something. If it's too high, it won't happen. Yet at the same time a certain baseline is needed to not end up being low hanging fruit for attackers.

I've also seen this, especially in security tools. The usability is often straight out of the 90s which keeps me wondering, who uses this voluntarily?

Re: 65% of employees bypass cybersecurity measures, new study finds

#74

Earlier quoted context omitted.

Why would you need to write your password on a post-it note if you use a password manager? Also, why would the note need to be specifically "on your desk"? If I really had no other choice than writing down a password, I would keep it in a more subtle/hidden place (my wallet, or my phone case, or in my locker). That's still not secure against a targeted attack, but I wouldn't be the lowest hanging fruit at least. Also…

I only use a password manager on my work computer because my boss forces me to. I find your question more surprising! Why would you use a password manager voluntarily? It's a torture device. I use it because my paycheck depends on it. What's your excuse? If I care about a service, I care enough to remember the password. Everything else might as well be a post-it-note on my desk... Though I prefer a simple one-word pa…

So that you can have secure and unique passwords for every site. It's pretty simple really. Prevents people from doing stupid things like putting their passwords on sticky notes for example.

Re: 65% of employees bypass cybersecurity measures, new study finds

#75
post #7

> Password Reuse: 49% of respondents use the same login credentials for multiple work applications, and 36% use the same credentials for personal and professional accounts. If your company has multiple things you need to log in to, its doing something wrong. Having company-wide single login system is really critical for good security. > 30% of employees share their workplace passwords with colleagues, effectively nul…

> If your company has multiple things you need to log in to, its doing something wrong.

It is inevitable. The SSO tax is often very high and for some products very difficult to justify. And then of course the large tail of smaller vendors that just don't support any SSO period.

> Normally sharing passwords should be harder than not sharing

Talk to marketing, they all share passwords to all the company media accounts because it is often the only way, those vendors don't support anything else.

Re: 65% of employees bypass cybersecurity measures, new study finds

#76
post #68
post #56

Earlier quoted context omitted.

You use PIM: https://learn.microsoft.com/en-us/entra/id-governance/privil... Basically you are eligible for your admin roles but you have to activate them first. Usually there are additional checks + notifications to other admins. These permissions are also only available for a set amount of time and then you will need to re request them :)

I don't understand the point of PIM. If some malicious actor has my token or controls my PC then what's stopping them from PIMing? Seems to me like it wastes my time more than anything else.

Good question actually! There are multiple layers that add to the security:

- Your login session as a user is normally valid for a day (~10 hours). But a pimmed session that gives you global admin permissions can be for example capped to max 1 hour.

- A normal login as a user can just require login + mfa. But if you want to PIM to certain admin roles you for example are required to use your yubikey as well. Yes it's an extra step but if your account is hacked they only have access to you as a user and not you as an admin unless they also capture your security key.

Also it creates some additional awareness for admins that they are now handling the keys of the kingdom and that the role that they just activated can do a lot of harm. In some organizations users get an admin account without fully understanding the consequences.

- It is way easier to audit. In normal circumstances a user's admin permissions are "always on". Once you start using pim you can also audit when and where additional permissions where requested. This is especially handy when you are monitoring everything and you get an alert saying "Hey sfn42 just requested global admin from a location that they normally do not request this. Can you look into this to make sure that it is legit?" With always on permissions this becomes way harder.

- Easier to manage via groups. You can have groups tied to eligible permissions and subsets of permissions. This is really handy once you start having external consultants who can request permissions via IGA (Identity Governance) policies.

Basically consultants can go to a url (https://myaccess.microsoft.com/) and request an "access package" that might contain 1 or more roles.

For example somebody who has to audit certain items in our organization can request a package that contains the needed admin roles and get automatically added to the correct groups. Once they request that package we can have automated processes (with multiple stages if needed) that first contact the teamlead of that person, and later on maybe another group of person(s) to approve that access.

These groups have access reviews done by the security team / app owner (weekly/monthly depending..) to make sure that all accesses are still needed. It is also really easy to let these permissions expire. So our auditor will have a valid account for the entire year but will have to re-request their permissions every 3 months (or whatever we choose).

This is also _really_ easy to audit :)

- When someone in our security team requests a role the rest of the team automatically receives an email so we know what is going on with our collegues :)

Re: 65% of employees bypass cybersecurity measures, new study finds

#77
If your measures include stuff like the password manager, which I need to use constantly, being set up to log me out every two minutes "for security purposes", you're damn right I will try to find a way to circumvent it. Each time you log me out it takes me a full minute to log back in, because I need to take out my phone and do the whole 2fa dance all over again. The first step anyone does is to log in to the password manager, and copy all the passwords they'll be needing for a while into notepad.

Re: 65% of employees bypass cybersecurity measures, new study finds

#79
post #71
post #45

Earlier quoted context omitted.

> If your company has multiple things you need to log in to, its doing something wrong. Having company-wide single login system is really critical for good security. It absolutely is, but it is only applicable to large corporations and won’t help any SMBs. The issue is that this functionality via LDAP/SAML/OODS is frequently locked behind enterprise subscription tiers that usually represent an extremely high markup o…

FreeIPA and Authentik works pretty well for me, I did some of this for my self with terraform for fun. Personally I don’t think it’s viable SMB who can’t hire a couple of sysadmins. But the documentation for FreeIPA is especially good. Personally wouldn’t use samba as windows DC, but one legacy windows server license seems reasonable if you are having a few hundreds of employees. In a previous job we’ve done Windows…

Oh absolutely, I am not talking about the provider side. Sure, it is not trivial, it is doable to set up a central directory and maintain it for relatively affordable.

The problem is with the software you are using. A lot of SaaS software has the connection to an SSO provider locked behind an enterprise tier.

Take Figma as an example. Their Pro tier is 15€/mo, their Organization tier is 45€/mo. A 3x markup for the lowers tier that supports SSO. And that is among the more reasonable prices. I’ve seen markups of 10x for an enterprise tier that is essential a pro tier + SSO.

Post reply on HN