| ▲ | jonplackett 5 hours ago | |||||||||||||
We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’ | ||||||||||||||
| ▲ | 11mariom 3 hours ago | parent | next [-] | |||||||||||||
They do not care about 'secure' part at all. | ||||||||||||||
| ||||||||||||||
| ▲ | bothers 7 minutes ago | parent | prev | next [-] | |||||||||||||
[dead] | ||||||||||||||
| ▲ | lbriner 4 hours ago | parent | prev [-] | |||||||||||||
That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain. The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know. I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"? | ||||||||||||||
| ||||||||||||||