← Back to context

Comment by xoa

6 hours ago

>You are paltering.

No, I'm honestly engaging with the topic and your post, vs tossing around insults.

>The premise was not to enhance security, but to design a world where security and productivity are not tradeoffs.

And I gave you examples, including engaging with your own example/question. You claimed that "most people would certainly be more productive if they hadn't had to authenticate themselves". But IDing and authenticating are different operations, people would need to ID regardless even in a world where no security was necessary. So if the marginal cost of auth over ID is zero, then by definition that means there is no tradeoff between security and productivity. Something like a security key/card is an example of accomplishing that. Plugging that in and typing 6 numbers or touching it is not merely no extra effort vs typing my user name alone, it's literally faster.

And again to other examples, anything transparent to the user is, again, by definition not an impact on productivity. For another not merely "common" but "near universal" example, see full disk encryption (which is now often the default even with no authentication at all). FDE definitely addresses a few classes of threat scenario. What do you argue is the tradeoff in productivity?