| ▲ | kulahan a day ago | |||||||||||||
Then there's no such thing as security. By the way, there are countless ways to account for humans. There are entire branches of engineering devoted to this. If you don't want someone to leave the bank with a pen customers use for signing checks, you just chain it to the desk. If you don't want the installer to forget to put the pen-chain in, make a photo of the chain part of the checklist required to get paid. If you want to... etc. The idea is that you determine an acceptable level of risk, then secure to that level. Maybe the acceptable level of risk chosen by companies is wrong. Maybe we need to increase that risk exposure via heavier fines and regulations. Maybe the cost of reducing that risk is too high already. Maybe we need to fund that. Maybe it's too confusing and we need to research better standard practices. I dunno. But this is not some unsolvable problem. | ||||||||||||||
| ▲ | 17 hours ago | parent | next [-] | |||||||||||||
| [deleted] | ||||||||||||||
| ▲ | awesome_dude 17 hours ago | parent | prev [-] | |||||||||||||
> Then there's no such thing as security. There really isn't Ask anyone seriously involved in security - whether computer science related, or in general. A thought experiment: Think about the most important secrets a country can have - now think how they are still discovered by competing countries, enemies, etc. As long as there are humans in the loop there is a known weakness. | ||||||||||||||
| ||||||||||||||