|
|
|
|
|
by xg15
3545 days ago
|
|
That clashes big time with the fact that more users than ever are online today with no clue at all about security. (And it's not practical to change that) So how would that new approach look? The de-facto solution today is that security is more and more delegated to device vendors and cloud providers. But that seems worse to me than delegating it to the admins of your organization that you know and trust. |
|
We need machines and global policy to help do this work and we need to stop putting faith in magic black boxes which we know will be thoroughly compromised (e.g.: all enterprise vendor equipment).
More on point, TLS 1.3 seems like a step in the right direction of thought: that you can improve your local security posture by improving the global posture.