Comment by tialaramex

13 hours ago

> It's tussle between two counter-acting forces at play.

It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]

I would love to hear about a world where security and productivity are not counter acting forces.

For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

If you can just create a world for that simple case, then I will rest my case.

  • Single-sign on is actually a really obvious and familiar example where you achieved better security (now all sixty five systems we use are protected by the same security, when we upgrade that security we're upgrading all sixty five systems) and yet you got better productivity because now I can get stuff done without battling two dozen authentication systems to do it, just sign in once.

    Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.

  • >I would love to hear about a world where security and productivity are not counter acting forces.

    Well, it's this one? Or at least for a wide array of practices. To take a trivial example, can you explain how switching encryption from DES to AES (a clear improvement to security) is counteractive to productivity? Of course not, whether it's AES or ChaCha20-Poly1305 or ROT13 the choice of underlying cipher is transparent to the higher level user/application. Or how about reducing memory overflow bugs? That improves security, while also reducing a certain class of crashes. How is reducing software crashes counteractive to productivity?

    Even if we take your silly example you clearly intend as a gotcha:

    >For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

    People have to identify themselves though in a multi-user environment anyway. Even completely putting aside any sort of security, we all of course have our own preferences for work environment, our own collections of data, etc etc etc. Duh. When we access a system (be it via GUI or CLI or web site) we need to say "I want to use xyz account" anyway. So the marginal cost to auth well can be zero. Using a password manager means "entering user name" and "entering user name and password at the same time" both have the exact same cost: 1 click of a button. Or if using a smartcard/USB PIV token or the like instead, it again can be the same effort: insert it, tap something.

    Certainly it's true that sometimes there are unavoidable tradeoffs. But there's a lot of low hanging fruit where things can be made more convenient/productive and more secure at the same time.

  • > most people would certainly be more productive if they hadn't had to authenticate themselves.

    ... right up to the moment when they aren't.

    I like to think of a law of conservation of productivity.

    Before: yours 100%, hacker's 0%.

    After: yours 0%, hacker's 100%.

    Nonsense, of course. Hacker's boost is nearer 100,000%.

    Fact is, modern computer power is inherently far more productive for bad than good. And the economic incentive follows.

    • Ah yes, you found the perfect argument to give sec people full and uncontrolled reign.

      Not is it probable that people will take over our system. But is it possible.