I’m gonna need everyone in security to internalize this.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove I’ve been working in this space for 20+ years. I agree more of us need to see cases like this. They are not corner cases. They are significant numbers of people in large populations and have to be considered when we design authentication systems. Thanks for sharing this.
-
I think about 95% of adults in wealthy countries have a smart phone
So about 95% have access to online registration ?
of th remaining 5% a lot are grouches like me, I don't have a smartphone but can obviously can use the internet
of the remaining what, 1% of adults who don't have a smartphone or a laptop, maybe 50% can access these things at a library ?
roughly ?
very few systems work smoothly for the last half percet
@failedLyndonLaRouchite @TindrasGrove the last half percent is still a huge number of people.
-
@rickf @TindrasGrove I understand that & what I am saying is: this already challenging enough - they shouldn’t have to commit to costs to participate or use basic services on top of everything else.
But as digitalization progresses, access becomes essential and you are forced to pay for it.
I’m addressing a different angle to the topic as well, so to say. In no way am I invalidating the statement.
-
@failedLyndonLaRouchite @TindrasGrove the last half percent is still a huge number of people.
absolutely
but as I tried , and possibly failed, to say, it is very hard to design systems that work well for the half percent -
@rickf @TindrasGrove sorry - I got a pretty hateful reply (which was deleted shortly after), so I felt a bit defensive.
-
@alxndr @derAndereAndre @TindrasGrove My grandma would be a lot more secure if she simply did not need a smartphone. There is no version of the technology that would be appropriate for her as her mind ages.
Ideally her home would have a small computer lab for those few computer tasks, and she would spend more of her time offline.
What I am saying is "We need to stop pressuring everyone to have a fucking smartphone"
-
@TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...
@tknarr @TindrasGrove But if we're talking about registration for an event that is probably at most three weeks away...
Why not use a 2fa that can be breached within months? The event will be over by then anyway, so you can just close down that account.
-
@patrizia @TindrasGrove Passkeys deeply terrify me due to the unchecked assumptions and requirements.
Like we should never assume a users device will always be accessable, reliable, and always owned by an individual.
-
@patrizia @TindrasGrove Passkeys deeply terrify me due to the unchecked assumptions and requirements.
Like we should never assume a users device will always be accessable, reliable, and always owned by an individual.
@Epic_Null @patrizia I am right there with you!
For my corporate work stuff where if they fail, I can have my manager verify my identity to the help desk to do a reset? Fine.
For things like my personal email where there’s not a way for me to reach someone who will reset? Fuuuuuuuuccckk noooo!!! The failure mode is just too much for me.
-
@Epic_Null @patrizia I am right there with you!
For my corporate work stuff where if they fail, I can have my manager verify my identity to the help desk to do a reset? Fine.
For things like my personal email where there’s not a way for me to reach someone who will reset? Fuuuuuuuuccckk noooo!!! The failure mode is just too much for me.
@TindrasGrove @patrizia Yeah a LOT of tech I have a problem with is forcing tech for corporarions onto home users.
This stuff has risks PERFECTLY managable with a functioning IT department, but disasterous for home users.
Bitlocker is a perfect example of this.
Security advocates model your threats challenge.
-
K Kichae crossposted this topicto General on
-
K Kichae moved this topic from World
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login