Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. they have a solid point, y'know.

they have a solid point, y'know.

Scheduled Pinned Locked Moved Uncategorized
5 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • munin@infosec.exchangeM This user is from outside of this forum
    munin@infosec.exchangeM This user is from outside of this forum
    munin@infosec.exchange
    wrote last edited by
    #1

    they have a solid point, y'know.

    users don't have meaningful agency here, but businesses sure the fuck do, and the way tech has treated users is creating perverse incentives and frustrations.

    munin@infosec.exchangeM tindrasgrove@infosec.exchangeT arclight@oldbytes.spaceA 3 Replies Last reply
    1
    0
    • munin@infosec.exchangeM munin@infosec.exchange

      they have a solid point, y'know.

      users don't have meaningful agency here, but businesses sure the fuck do, and the way tech has treated users is creating perverse incentives and frustrations.

      munin@infosec.exchangeM This user is from outside of this forum
      munin@infosec.exchangeM This user is from outside of this forum
      munin@infosec.exchange
      wrote last edited by
      #2

      if you want users to take security seriously?

      gotta give them some reason to think it will matter.

      1 Reply Last reply
      0
      • R relay@relay.mycrowd.ca shared this topic
      • munin@infosec.exchangeM munin@infosec.exchange

        they have a solid point, y'know.

        users don't have meaningful agency here, but businesses sure the fuck do, and the way tech has treated users is creating perverse incentives and frustrations.

        tindrasgrove@infosec.exchangeT This user is from outside of this forum
        tindrasgrove@infosec.exchangeT This user is from outside of this forum
        tindrasgrove@infosec.exchange
        wrote last edited by
        #3

        @munin
        I can never use online banking, and my bank may still allow my account to be compromised.

        I can never fill out a form online with my address, but my address is still online because “public record”

        I can never buy anything online, never use a credit card, but the combination of ALPR and security cameras means my shopping habits are still known when I shop in-person using cash.

        Yeah, consumers are not the problem here.

        1 Reply Last reply
        0
        • munin@infosec.exchangeM munin@infosec.exchange

          they have a solid point, y'know.

          users don't have meaningful agency here, but businesses sure the fuck do, and the way tech has treated users is creating perverse incentives and frustrations.

          arclight@oldbytes.spaceA This user is from outside of this forum
          arclight@oldbytes.spaceA This user is from outside of this forum
          arclight@oldbytes.space
          wrote last edited by
          #4

          @munin I just posted about an attack on/using agentic finance bots that cost someone $200k. https://oldbytes.space/@arclight/116587393934910011

          I still can't stop laughing at a Trojan NFT.

          1 Reply Last reply
          0
          • tychotithonus@infosec.exchangeT This user is from outside of this forum
            tychotithonus@infosec.exchangeT This user is from outside of this forum
            tychotithonus@infosec.exchange
            wrote last edited by
            #5

            @phessler

            Each individual user may not consider a given credential as worth needing MFA, but since most users reuse passwords, it's arguably better move for the ecosystem and site operators to require some kind of MFA. Otherwise, if one site gets popped, a wave of user accounts could be abused in bulk and require operator intervention. Whether or not mass lockout/reset is inconvenient enough for the individual user to think MFA is a good trade-off may vary.

            @munin

            1 Reply Last reply
            1
            0
            • R relay@relay.infosec.exchange shared this topic
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups