← Back to context

Comment by zkmon

12 hours ago

I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.

It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.

You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)

  • Unless of course, you need to unlock your password manager, which is not integrated with your browser, because corporate IT doesn't allow browser extensions or desktop apps so you're bound to a web app ...

  • Until security forces the password manager session to expire after 1 hour, and forces the master password to be 16 char long with a combination of lower, upper, digit, punctuation, moon phase, astrological sign. And then they force you to change it every 2 months, and you can't reuse it until the next time Halley's comet is in the solar system.

    You're missing the systemic problem the parent is talking about.

    • None of those hypotheticals apply in a company where "123456" was allowed as a password to begin with.

      And if even if they did, which of these two is easier?

      1. Typing your 16 char password with the current moon phase once an hour, and remembering the new one every time a comet passes

      2. Pressing your password manager keyboard shortcut (or tapping your yubikey) once an hour, the exact same action that never changes for the rest of your life

      1 reply →

With two people in the company, there is not a lot of room for corporate games though.

> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.

> It's tussle between two counter-acting forces at play.

It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]

  • I would love to hear about a world where security and productivity are not counter acting forces.

    For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

    If you can just create a world for that simple case, then I will rest my case.

    • Single-sign on is actually a really obvious and familiar example where you achieved better security (now all sixty five systems we use are protected by the same security, when we upgrade that security we're upgrading all sixty five systems) and yet you got better productivity because now I can get stuff done without battling two dozen authentication systems to do it, just sign in once.

      Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.

      6 replies →

    • >I would love to hear about a world where security and productivity are not counter acting forces.

      Well, it's this one? Or at least for a wide array of practices. To take a trivial example, can you explain how switching encryption from DES to AES (a clear improvement to security) is counteractive to productivity? Of course not, whether it's AES or ChaCha20-Poly1305 or ROT13 the choice of underlying cipher is transparent to the higher level user/application. Or how about reducing memory overflow bugs? That improves security, while also reducing a certain class of crashes. How is reducing software crashes counteractive to productivity?

      Even if we take your silly example you clearly intend as a gotcha:

      >For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

      People have to identify themselves though in a multi-user environment anyway. Even completely putting aside any sort of security, we all of course have our own preferences for work environment, our own collections of data, etc etc etc. Duh. When we access a system (be it via GUI or CLI or web site) we need to say "I want to use xyz account" anyway. So the marginal cost to auth well can be zero. Using a password manager means "entering user name" and "entering user name and password at the same time" both have the exact same cost: 1 click of a button. Or if using a smartcard/USB PIV token or the like instead, it again can be the same effort: insert it, tap something.

      Certainly it's true that sometimes there are unavoidable tradeoffs. But there's a lot of low hanging fruit where things can be made more convenient/productive and more secure at the same time.

      2 replies →

    • > most people would certainly be more productive if they hadn't had to authenticate themselves.

      ... right up to the moment when they aren't.

      I like to think of a law of conservation of productivity.

      Before: yours 100%, hacker's 0%.

      After: yours 0%, hacker's 100%.

      Nonsense, of course. Hacker's boost is nearer 100,000%.

      Fact is, modern computer power is inherently far more productive for bad than good. And the economic incentive follows.

      1 reply →

It's not that hard to enable 2fa & force password manager usage. And it's not that hard to use it. In fact a pw manager alone is much more convenient than remembering passwords. The only people I know who "can't remember their passwords and are locked out" are people who don't use the pw manager and have dogs*it passwords with tiny variants they forget. They often need multiple attempts to log in anywhere. Yeah 2fa & pw manager is a tick more complicated but it's not like it take hours, it takes minutes per day. And you protect against stuff like this. No sympathy, sorry.

Productivity and Aesthetics could also be said to be counter acting forces. Or really anything that requires contemplation. I think the problem is in how some people define "productive". Is it productive to have significant security problems which cause more work?

Sorry, if your job title implies even a smidgen of security responsibility, you deserve to be fired for "123456" as your password. The person who was an administrator would fall under this label. Besides, "If productivity is not your goal, then security is not my goal." is what results in draconic security measures, because employees can't be trusted AT ALL. I really don't understand your comment.

Just because a task is hard it should never absolve anything. Guy could just have quit if he didn't want the responsibility.

  • The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.

Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"

  • The guys who are really into keyboard layouts would argue vehemently that 123456 is more ergonomic as it's an "inward roll" vs 6 consecutive presses of a key that aligns to the pinky

  • I'm not sure, I think it's a little more ergonomical to hit six different keys compared to hitting a single key precisely six times.