Hacker News new | ask | show | jobs
by spjt 2 days ago
Yeah we were trying to develop an internal corporate MacOS desktop app and the amount of shit I had to go through just to get it to the point where someone who isn't a developer was able to run it was absolutely insane. In the end a lot of this is probably even counterproductive as people get used to these sort of things coming with instructions to disable all security and paste these sudo commands into a terminal to get it running...
1 comments

It has been a known thing in security for what has to be decades now that taking a security/usability trade off in favor of "security" is the fast way to train users to mash the "allow all" button from muscle memory, thereby severely impairing security.

The premise of the scary banner has to be that the first time the user has ever seen it is when there is actually something wrong.

This is, of course, fully incompatible with the corporate incentive to present the scary banner whenever an honest third party hasn't paid them the danegeld or satisfied a bureaucratic process documented by Franz Kafka. If the thing you care about is actually security.