• jj4211@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    2 days ago

    One complaint I have is browser insistence that a site must have a proper certificate to work at all.

    I provide self hosted software with passkey support and probably over 90 percent of my users never set up property certificates due their private networks. So the passkey function is impossible for them.

    Which means they must use passwords. Which are far worse in this scenario. The practical risk either way is arguably low for them, but to take a more mitm/phishing resistant technique and then force it to not work because mitm or phishing might be in play…

    • setVeryLoud(true);@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      14 hours ago

      I literally just completed a Secure Code Warrior formation mandated by work, and one of the videos states “websites with expired certificates transit your information unencrypted, leaving you exposed to hackers” 🤦 like bruh you’re supposed to know better, you teach cybersecurity for fuck’s sake.

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        31 minutes ago

        I’ve met two sorts of dedicated cybersecurity experts:

        The sort that only understands how to click ‘scan’ in various tools and repeat output and browser error messages without understanding nuance. Had a fun incident where the nuance really mattered in interop with a popular product in my niche, company said we must not implement the interop because it was hopelessly insecure. When I pushed back on the nuance (folks behind the ‘vulnerable’ tech had way much more sway in the market than we did), got told I should really educate myself and read the paper on the vulnerability to understand that my proposol to workaround it was impossible. For one glorious moment in my career, I got to tell them to look at the paper again and specifically the author (I had written up the vulnerability in the first place). After a brief shock though, he still went back to even though I may have found it and explained in key detail, I still must not understand the implications…

        Then there’s those that understand and can engage in nuance, but will still say inaccurate stuff, because they’ve learned being accurate and precise with the lay person doesn’t work too well, and easier to just say “big scary” instead of explaining precisely the threat model and rationale. I will confess on a number of threads I have seen this happen and let it go without correction because correcting wouldn’t have changed the core of the material, but would make the discussion go on even longer and waste more time. I personally can’t bring myself to outright say the wrong things, but I do understand why it’s the more practical strategy sometimes.

      • Kairos@lemmy.today
        link
        fedilink
        English
        arrow-up
        3
        ·
        14 hours ago

        Computing and by extension cybersecurity has a lot of mouth-breather idiots because it’s so new.

        • jj4211@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          29 minutes ago

          It’s not so new anymore, however, it is widely known as an “easy” way to a strong six-figure salary, so we have a lot of gold-rush mouth-breather idiots that never would have gotten into this in the first place if not for the dollar signs. Really started to turn south around the time dot-com inspired early career people to get in on the bubble.