Live data from Hacker News

65% of employees bypass cybersecurity measures, new study finds

forbes.com

81–90 of 97 posts

Re: 65% of employees bypass cybersecurity measures, new study finds

#82

Earlier quoted context omitted.

Why would you need to write your password on a post-it note if you use a password manager? Also, why would the note need to be specifically "on your desk"? If I really had no other choice than writing down a password, I would keep it in a more subtle/hidden place (my wallet, or my phone case, or in my locker). That's still not secure against a targeted attack, but I wouldn't be the lowest hanging fruit at least. Also…

I only use a password manager on my work computer because my boss forces me to. I find your question more surprising! Why would you use a password manager voluntarily? It's a torture device. I use it because my paycheck depends on it. What's your excuse? If I care about a service, I care enough to remember the password. Everything else might as well be a post-it-note on my desk... Though I prefer a simple one-word pa…

> If I care about a service, I care enough to remember the password.

Wait, no; you just said,

> My biggest pet peeve is when the platform forces me to add certain special characters to my password, then I need to write down my altered password and put it on a post-it note on my desk to remember it.

So can you remember passwords or not?

> Though I prefer a simple one-word password that I can easily remember.

See, that makes it sound like you can't remember secure passwords and just want to use insecure passwords.

Re: 65% of employees bypass cybersecurity measures, new study finds

#83
post #29

I work at a large software company and recently documented the number of steps it takes me every morning to fully log into every system I need for work. I stopped at 37. And every year in response to all the breaches in the news the company spends more money to hire another security team who simply pile on another redundant layer on top. The industry has jumped the shark when it comes to IT security. It's the corpora…

Why is the company hiring a new security team each year? Where the ownership and strategic thinking? Sounds like your organisation is extremely dysfunctional, and the ridiculous security you have is a symptom of that. None of that is inevitable.

Nor is it uncommon though.. That description sounds very familiar.

Re: 65% of employees bypass cybersecurity measures, new study finds

#84
post #76
post #68

Earlier quoted context omitted.

I don't understand the point of PIM. If some malicious actor has my token or controls my PC then what's stopping them from PIMing? Seems to me like it wastes my time more than anything else.

Good question actually! There are multiple layers that add to the security: - Your login session as a user is normally valid for a day (~10 hours). But a pimmed session that gives you global admin permissions can be for example capped to max 1 hour. - A normal login as a user can just require login + mfa. But if you want to PIM to certain admin roles you for example are required to use your yubikey as well. Yes it's…

Thanks for the response! You pretty much just described exactly how it works in the organization I work for, as an outside contractor.

But PIM has a max duration of 8 hours and does not require additional authentication like yubikey, it doesn't even require that I authenticate again with my regular MFA login.

In practice everyone just writes what amounts to nothing as their reason. We literally write our team name.

It's also badly set up so all kinds of bullshit like viewing application logs requires PIM and nobody really knows how it works so we just request all the roles instead of considering which one we need because it's all just a big box of magic that few people actually understand. And we do so pretty much every day because we always need to do something in Azure.

So with the way we use it it still seems pointless to me, even with your explanations. Maybe we get some small benefits from it but for the most part it seems like security posturing to me.

Re: 65% of employees bypass cybersecurity measures, new study finds

#85
post #11

When I was at MS, I wrote a detailed guide how to trick the central IT system into thinking that your machine had the antivirus software running when it did not. It eventually, years later, got forwarded back to me as some sort of underground currency (with my authorship removed).

I was reasonably impressed by MSFT IT when I worked there. I was primarily a BYOD Mac user and only had to deal with IT two to three times over the course of 8 years. I took it for granted at the time because I came from the startup work where you're basically your own IT person. But other large companies after Microsoft clearly demonstrated to me that Microsoft is on top of their shit and the average is fucking terr…

This was in the 90s, other than the AV issue, they got high marks from me. I even had a linux and freebsd machine running attached to the corp net with no issues, they did not touch MS infra. The average is indeed terrible.

Re: 65% of employees bypass cybersecurity measures, new study finds

#86
post #47

Earlier quoted context omitted.

Why would you make such a blanket generalization? The security team where I work is comprised of competent professionals and generally nice people to boot. Our CISO is a great guy to have a beer with. We've had our disagreements, but they've been of the "smart people championing conflicting business values having a reasonable discussion" variety.

They're all great guys with each other. Do a test. Go to distant office and call IT pretending to be the person who works in that office, with his/her cooperation. See how fast the problem is solved and how you are treated.

I mean, we're a remote company. I work in software, not IT. YMMV I guess. I don't think demonizing an entire department on the basis of a job title is a very intelligent or humane thing to do, and it doesn't resonate with my lived experience.

Re: 65% of employees bypass cybersecurity measures, new study finds

#88
post #40

Earlier quoted context omitted.

Because of MITM-ing TLS with their own certificates, they could also stop you from dumping tons of code into an LLM prompt by blocking all public LLMs (or even all sites not on an allowlist). The reason it's silly is really that you can always take "secrets" with you, be it by taking photos with your phone ("lets ban phones") or memorizing or writing on paper. Security is useful when it prevents accidental, inadverte…

You overestimate the intelligence of a lot of people. We have caught attempts at exfiltration over channels we can easily monitor. Is it perfect? No. Can reasonably intelligent people find a way around them? Sure. But we are still going to control that information flow where we can.

So, as the OP claims, it is working for the 35% of the employees, right?

And it likely inconveniences a full 100%.

Does that sound like a smart trade-off?

Re: 65% of employees bypass cybersecurity measures, new study finds

#89
post #23

Earlier quoted context omitted.

And that still leaves someone not being able to do their job for a number of hours or a number of days while those "reasonable discussions" are ongoing. It is a hard problem, and the implied solution of "be even more restrictive" is only going to make matters worse.

Those discussions I consider part of the job educating users is very important.

If it's 35% successful as the OP claims, do you think it's working?

Re: 65% of employees bypass cybersecurity measures, new study finds

#90
post #88

Earlier quoted context omitted.

You overestimate the intelligence of a lot of people. We have caught attempts at exfiltration over channels we can easily monitor. Is it perfect? No. Can reasonably intelligent people find a way around them? Sure. But we are still going to control that information flow where we can.

So, as the OP claims, it is working for the 35% of the employees, right? And it likely inconveniences a full 100%. Does that sound like a smart trade-off?

What is the alternative?

I have actually worked in places that prevented all personal electronic devices in the building, had security guards and bag searches on every floor and no internet access on your desktop. You don't know what inconvenience looks like!

Post reply on HN