Hacker News new | ask | show | jobs
by expertentipp 930 days ago
> keeping the bad guys out AND keeping the good guys in.

YES

> Because they don't get held to account for obstructing everyone else's work, they naturally do every ass-covering piece of security theatre they can - they don't suffer any consequences.

Every time you push back on some ridiculous policy they'll respond with ironic smirk or shrug (are you seriously forcing password change monthly and keeping hashes of the last 10 passwords?!). Nowadays basically every corporate security policy forces employees to install some kind of crappy DUO/whatever (FUCK YOU CISCO) app on a private phone, work phone is a rare occurence nowadays ("everyone have their own smartphone anyway"). It's never a TOTP which somehow works perfectly fine on many other crucial services. One might think we're all competent tech folks, but they're vicious malicious cunts.