Our Approach to Employee Security Training
pagerduty.com
Our Approach to Employee Security Training
1–10 of 76 posts
Re: Our Approach to Employee Security Training
#2Re: Our Approach to Employee Security Training
#3Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic lists" when they want to read more about rainbow tables. Let alone the completely mad communication you'll get with people in the company.
> We implemented magic sodium suffix in our application this week, attackers won't be able to use magic lists when our magic data leaks.
>> What?
> You know, irreversible magic?
>> ...
Re: Our Approach to Employee Security Training
#4> The mere mention of the word “hashing” is probably enough to make non-technical employees’ eyes gloss over. So instead I just call it “Magic”.
What..? Why state a principle and then tell us how you violate it a few sentences later.
Re: Our Approach to Employee Security Training
#5> 2. Don’t shy away from technical details. > The mere mention of the word “hashing” is probably enough to make non-technical employees’ eyes gloss over. So instead I just call it “Magic”. What..? Why state a principle and then tell us how you violate it a few sentences later.
Re: Our Approach to Employee Security Training
#6Re: Our Approach to Employee Security Training
#7If they can't understand hashing then there's no hope of teaching them security so why even bother?
Re: Our Approach to Employee Security Training
#8> Concepts such as rainbow tables can then be explained without having to refer to the actual name; we can just demonstrate that you can create a lookup and call it a “magic list”. Names are there for a reason. "magic list" instead of "rainbow table", seriously? You're teaching a concept and then giving it a slightly different name just to make it sound more edgy. People won't be able to find anything about "magic li…
Also, if you continue to RTFA,
> That said, I didn’t want to mislead people. So we chose to be clear to them that there is a technical term; it’s just not going to be important for the rest of the content.
If it's someone job to provide reports/updates on something related to the concept, yes they should know it, for anyone else in a non-technical role, why does it really matter?
Re: Our Approach to Employee Security Training
#9If they can't understand hashing then there's no hope of teaching them security so why even bother?
Re: Our Approach to Employee Security Training
#10I can highly recommend giving it a try. The first few levels of difficulty are easy to spot, but it's been eye opening for me how sophisticated phishing emails can get.