• jj4211@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 hour ago

    I’ve met two sorts of dedicated cybersecurity experts:

    The sort that only understands how to click ‘scan’ in various tools and repeat output and browser error messages without understanding nuance. Had a fun incident where the nuance really mattered in interop with a popular product in my niche, company said we must not implement the interop because it was hopelessly insecure. When I pushed back on the nuance (folks behind the ‘vulnerable’ tech had way much more sway in the market than we did), got told I should really educate myself and read the paper on the vulnerability to understand that my proposol to workaround it was impossible. For one glorious moment in my career, I got to tell them to look at the paper again and specifically the author (I had written up the vulnerability in the first place). After a brief shock though, he still went back to even though I may have found it and explained in key detail, I still must not understand the implications…

    Then there’s those that understand and can engage in nuance, but will still say inaccurate stuff, because they’ve learned being accurate and precise with the lay person doesn’t work too well, and easier to just say “big scary” instead of explaining precisely the threat model and rationale. I will confess on a number of threads I have seen this happen and let it go without correction because correcting wouldn’t have changed the core of the material, but would make the discussion go on even longer and waste more time. I personally can’t bring myself to outright say the wrong things, but I do understand why it’s the more practical strategy sometimes.

    • setVeryLoud(true);@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      30 minutes ago

      I’m the kind of 'tism where I can’t get myself to tell white lies and will argue up and down until the truth prevails… sometimes to my own detriment, but I really like to understand the underlying mechanisms and the nuance underneath things, otherwise I feel lied to, and I thusly can’t get myself to feel like I am deceiving others.

      Please share the paper, I’m curious!

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        13 minutes ago

        I’m trying to stay too anonymous, the paper is of super niche interest and the vulnerability comes down to a popular configuration being vulnerable, but a hardened configuration is possible, but requires randomizing some data that folks tend to leave non-random because it’s the lazier way to set that up and it wasn’t formerly recognized that the randomness of the data had security implications.