Hacker News new | ask | show | jobs
by quantummagic 38 days ago
Do you hold that same opinion for the training and testing of pilots and surgeons? Do you want to step on a plane with a pilot who is only there because we are too nice to assign individual blame for his inability to do the job properly? Do you want to be going into open heart surgery in a system that dismisses the idea of individual blame when analyzing the outcomes associated with each surgeon? Having no idea if the man cutting into you, has previously had great outcomes or poor outcomes?
1 comments

You’re both imagining different scenarios.

Scenario 1: 20% of staff tested failed. Individual targeting is pointless because the issue is systemic. This has happened in aviation, it’s common for accident investigators to conclude that the entire company culture (or even the entire industry) has failed to handle a problem. They don’t waste time in cases like this pointing at individuals.

Scenario 2: you test very regularly and nobody fails the tests. Except Bob, he fails the tests. In this scenario, your threat analysis document will recommend retraining, firing, or restricting Bob specifically.

Scenario 2 almost never happens because nobody has data that good. If your sampling frequency or ability to conduct tests are limited, no specific sample is enough to cover the entire problem. If you focus on a punishing (or just re-educating) the 20% who failed then your next test will fail for (potentially) 20% of the 80% who weren’t retrained, and thus didn’t learn anything.

TLDR: you need to choose the approach based on the situation, but we collectively tend to treat security poorly enough that we’re almost never in the fortunate situation where scenario 2 fits.