| ▲ | woodruffw 4 hours ago | ||||||||||||||||
The conventional meaning of “security theater” requires performance instead of effective action. But the author doesn’t reach that meaning: they claim that cooldowns don’t universalize, which then gets misconstrued into “security theater.” I don’t agree with either claim: I don’t think they’re security theater, and I do think they universalize, contingent on there being security parties that are incentivized to scan packages. The latter is a big assumption, but I think it’s a win for us either way: if supply chain companies are actually capable of defending us, then we win. But if it turns out they can’t serve as the cooldown vanguard, then we have great evidence that they shouldn’t be trusted at all. | |||||||||||||||||
| ▲ | outloudvi 4 hours ago | parent [-] | ||||||||||||||||
Thanks for your explanation on the definition of "security theater"! > But if it turns out they can’t serve as the cooldown vanguard, then we have great evidence that they shouldn’t be trusted at all. If they cannot serve as the cooldown vanguard, we are indeed going to realize they are not trustable, but by the time the damage has already been done. Therefore, if companies want to prevent the damage as much as possible, I believe they should do the scan by themselves. | |||||||||||||||||
| |||||||||||||||||