Live data from Hacker News

Comparing how security experts and non-experts stay safe online

googleonlinesecurity.blogspot.com

91–100 of 122 posts

Re: Comparing how security experts and non-experts stay safe online

#91

But are the security experts actually safer online? The study seems to assume that they are. It may be a fair assumption, but it would be interesting to know if it actually is true or not. It would also help validate the security practices. If it turns out that the security experts got infected just as much, or only slightly less than the non-experts, then following their practices might not be worth the effort...

> But are the security experts actually safer online?

s/security experts/technical users/

Yes, we are. Whenever you see a laptop full of malware, that's a non-technical user. We're not safe from it entirely, nobody is 100% safe, but we're in much better shape than the regular folks.

Re: Comparing how security experts and non-experts stay safe online

#92
post #86

Earlier quoted context omitted.

When you have 1.6 billion users, every time you waste 5 minutes of their time installing updates and rebooting, that wastes 190 human lifetimes worth of man-hours. I know that Microsoft does not properly account for this when deciding how much effort to allocate to making updates less intrusive.

Most people will not stare at the screen for 5 minutes while it's updating. They will be doing non-computer tasks in the meantime. Also, this ignores the ability for the updates to be postponed[1] until a convenient time (at lunch?, after work?), which means the lost productivity is reduced to the time it takes to restore the workspace. [1] Even with windows 10's forced updates, I still think it's possible to postpon…

Great, so reduce the time estimate by an order of magnitude. Now you're only wasting 19 human lifetimes per update. Hooray?

Re: Comparing how security experts and non-experts stay safe online

#93
post #71

But are the security experts actually safer online? The study seems to assume that they are. It may be a fair assumption, but it would be interesting to know if it actually is true or not. It would also help validate the security practices. If it turns out that the security experts got infected just as much, or only slightly less than the non-experts, then following their practices might not be worth the effort...

Very good question, but I'm not sure how you imagine this could be addressed. Security experts may use a lot more password managers and want to use unique passwords, but you could say that's just because they have a lot more accounts than normal people. Most people have a couple accounts for social networking, their bank, perhaps a local library... experts usually work in the field, spend their days online in an offi…

I don't think that you can correlate number of accounts vs security awareness of the user.

Some users may be social butterflies, and some may be hermits. Independent of their level-of-security-awareness.

Re: Comparing how security experts and non-experts stay safe online

#94
post #86

Earlier quoted context omitted.

When you have 1.6 billion users, every time you waste 5 minutes of their time installing updates and rebooting, that wastes 190 human lifetimes worth of man-hours. I know that Microsoft does not properly account for this when deciding how much effort to allocate to making updates less intrusive.

Most people will not stare at the screen for 5 minutes while it's updating. They will be doing non-computer tasks in the meantime. Also, this ignores the ability for the updates to be postponed[1] until a convenient time (at lunch?, after work?), which means the lost productivity is reduced to the time it takes to restore the workspace. [1] Even with windows 10's forced updates, I still think it's possible to postpon…

This is the wrong objection. If only 10% of users lose 5 minutes each, that's... 19 lifetimes' worth of man-hours, which is still excessive. The real reason for not doing rebootless updates is that they're hard to implement, and hard to implement in such a way that they create a risk of problems much bigger than losing 5 minutes (like data loss or security vulns staying open).

Re: Comparing how security experts and non-experts stay safe online

#95

[Non-experts] mistakenly worry that software updates are a security risk. I think this betrays a lack of thought about the risks to non-experts. Tons of malware masquerades as legitimate updates, and non-experts don't always have the knowledge to distinguish legitimate updates from malicious ones. Therefore, to non-experts software updates are a security risk. Edit: And this is why Chrome's policy of updating automat…

> And this is why Chrome's policy of updating automatically and completely silently is the right thing to do Not everyone is hooked up to unlimited broadband 24/7. To anyone who is frequently jumping between capped satellite & 3G/4G networks, silent auto-updating software not only unexpectedly slows down your already non-ideal connection, but also eats up lots of your capped data. Lots of services tend to forget abou…

The proliferation of mobile devices and the convergence of mobile and traditional end user operating systems is solving this one. Android and Windows 8.1 both have the ability to mark an arbitrary WiFi network as metered, and many core services as well as third party apps will happily discriminate between unlimited WiFi and metered WiFi/cellular connections.

Re: Comparing how security experts and non-experts stay safe online

#96

Earlier quoted context omitted.

Browsing makes sense, but why email? Unless you run an OS and email client that 1) renders HTML mail by default (making you vulnerable to browser engine attacks) or 2) makes it too easy to run executable email attachments, then is an email client really higher risk than many other pieces of software?

Any time you provide a vector for an attacker, you run the risk of being exploited. Email is even worse than web browsing, because an attacker has the ability to send it to you, rather than waiting for you to go to their site. I would never claim to know my email-renderer so well that I was 100% confident that it didn't have any attack vectors, particularly with all the crazy things you can do with unicode nowadays -…

Even more straightforward still to hire a Mechanical Turk to read your email to you over the phone, and there's no risk of viruses capable of VM breakout!

Re: Comparing how security experts and non-experts stay safe online

#97
post #8
post #4

The thing that software security people do that most normal people don't do is: browsing and accessing email in a virtual machine, not their actual machine.

Can we settle for containers instead? For example, running Chrome in a Docker container. Why not? Drawbacks? Security risks? Feasibility? I understand that users download things but personally I can't recall doing that in recent memory, other than things like news/tech spec PDFs for later review. Moving downloaded files out of the browser's container would involve a fair bit of ceremony (physically selecting files/fo…

Docker does not provide any security.

Re: Comparing how security experts and non-experts stay safe online

#98

But are the security experts actually safer online? The study seems to assume that they are. It may be a fair assumption, but it would be interesting to know if it actually is true or not. It would also help validate the security practices. If it turns out that the security experts got infected just as much, or only slightly less than the non-experts, then following their practices might not be worth the effort...

> But are the security experts actually safer online? s/security experts/technical users/ Yes, we are. Whenever you see a laptop full of malware, that's a non-technical user. We're not safe from it entirely, nobody is 100% safe, but we're in much better shape than the regular folks.

Citation needed!

Not just being pedantic here for the sake of it, I think it would be good to know how much safer experts generally are. Just saying "we're better than them!" isn't very convincing or useful.

Re: Comparing how security experts and non-experts stay safe online

#99
post #86

Earlier quoted context omitted.

Most people will not stare at the screen for 5 minutes while it's updating. They will be doing non-computer tasks in the meantime. Also, this ignores the ability for the updates to be postponed[1] until a convenient time (at lunch?, after work?), which means the lost productivity is reduced to the time it takes to restore the workspace. [1] Even with windows 10's forced updates, I still think it's possible to postpon…

Great, so reduce the time estimate by an order of magnitude. Now you're only wasting 19 human lifetimes per update. Hooray?

I have some bad news for you; companies imposing costs on others to reduce their own cost is extremely common: https://en.wikipedia.org/wiki/Externality
Post reply on HN