← Back to context

Comment by xoa

11 hours ago

>I would love to hear about a world where security and productivity are not counter acting forces.

Well, it's this one? Or at least for a wide array of practices. To take a trivial example, can you explain how switching encryption from DES to AES (a clear improvement to security) is counteractive to productivity? Of course not, whether it's AES or ChaCha20-Poly1305 or ROT13 the choice of underlying cipher is transparent to the higher level user/application. Or how about reducing memory overflow bugs? That improves security, while also reducing a certain class of crashes. How is reducing software crashes counteractive to productivity?

Even if we take your silly example you clearly intend as a gotcha:

>For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

People have to identify themselves though in a multi-user environment anyway. Even completely putting aside any sort of security, we all of course have our own preferences for work environment, our own collections of data, etc etc etc. Duh. When we access a system (be it via GUI or CLI or web site) we need to say "I want to use xyz account" anyway. So the marginal cost to auth well can be zero. Using a password manager means "entering user name" and "entering user name and password at the same time" both have the exact same cost: 1 click of a button. Or if using a smartcard/USB PIV token or the like instead, it again can be the same effort: insert it, tap something.

Certainly it's true that sometimes there are unavoidable tradeoffs. But there's a lot of low hanging fruit where things can be made more convenient/productive and more secure at the same time.

You are paltering.

The premise was not to enhance security, but to design a world where security and productivity are not tradeoffs.

  • >You are paltering.

    No, I'm honestly engaging with the topic and your post, vs tossing around insults.

    >The premise was not to enhance security, but to design a world where security and productivity are not tradeoffs.

    And I gave you examples, including engaging with your own example/question. You claimed that "most people would certainly be more productive if they hadn't had to authenticate themselves". But IDing and authenticating are different operations, people would need to ID regardless even in a world where no security was necessary. So if the marginal cost of auth over ID is zero, then by definition that means there is no tradeoff between security and productivity. Something like a security key/card is an example of accomplishing that. Plugging that in and typing 6 numbers or touching it is not merely no extra effort vs typing my user name alone, it's literally faster.

    And again to other examples, anything transparent to the user is, again, by definition not an impact on productivity. For another not merely "common" but "near universal" example, see full disk encryption (which is now often the default even with no authentication at all). FDE definitely addresses a few classes of threat scenario. What do you argue is the tradeoff in productivity?