Hacker News new | ask | show | jobs
by brookst 41 days ago
The “attackers only have to win once” principle is core to infosec; a company has to ensure every single employee rejects every single phishing attempt every single time, an attacker just has to get one employee once.

But I think people misinterpret the principle to mean that only perfect solutions have any value.

When in reality defense in depth is the opposite principle: you scan incoming emails for phishing, and that’s good but imperfect. You do mandatory training, and that’s good but imperfect. You use RBAC to limit blast radius, and that’s good but imperfect. And so on.

Among tech people, especially on HN for some reason, there’s this odd thinking style that goes: 1) company announces security measure, 2) the measure could possibly limit my freedom to do whatever I want with the company’s products, 3) I don’t like that, 4) I can come up with scenarios where the security measure is not sufficient, entirely on its own, to address the claimed risk, 5) therefore the security measure does no good at all, 6) therefore this is a PR smokescreen to disguise their desire to capriciously fuck with me out of pure malice, and I am angry about it