venta: (Default)
[personal profile] venta
I fear the apocalypse may be nigh. Certainly the end times are near.

Bruce Schneier is quoting Jeremy Clarkson.

Date: 2010-03-31 10:53 am (UTC)
From: [identity profile] venta.livejournal.com
It's a fairly firmly-held theory of mine that the weak points in pretty much any security policy are the people involved. Even if you work in an office where you need a passcard to get in, how many people will actually refuse to hold open a door to let another person in? Unless you work somewhere where security is very very important, I reckon politeness will beat security any day.

All the oddities with (say) bank security over the phone and so on seem to be caused by the bank employee Just Not Getting It - and hence they apply the rules quite blindly, and don't understand what is or is not a real risk.

Date: 2010-03-31 11:32 am (UTC)
From: [identity profile] bateleur.livejournal.com
Indeed.

I've actually has a few cases where bank employees have even (potentially) compromised security by promoting bad policy. They phone me up and then ask for security details. I respond by asking them to prove they're the bank and they are completely baffled, as though nobody's ever said this to them before!

Date: 2010-03-31 11:48 am (UTC)
From: [identity profile] venta.livejournal.com
Yes, that's one of the cases that led me to this theory.

Not only have they been baffled, but even after I've explained why I want them to do this, they don't seem to understand why it's important.

In fairness, I do think the bank ought to have thought this through and introduced a stage where they verify their identity, or at least included an extra bit of script in case the user asks for it. By the time I've answered the phone they've already got one-factor security ("something I have") on who I am, so a sensible policy would encourage people like me to demand something from them before I hand over information.

The best come-back I heard (from someone asking for my DOB and mother's maiden name) when I asked that they verify their ID first was "but I only want your DOB and mother's maiden name, anyone can get hold of those". Er... yes, they can. So why are you using them for your security checks?

Date: 2010-03-31 12:38 pm (UTC)
From: [identity profile] bateleur.livejournal.com
That's quite special!

Profile

venta: (Default)
venta

December 2025

S M T W T F S
 123456
78910111213
14151617181920
212223 24252627
28293031   

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Dec. 28th, 2025 12:20 pm
Powered by Dreamwidth Studios