Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Certainly. But I think then one has to factor in issues of cost and complexity. Technological tools can take care of "low-hanging" fruit, but can't be so strict as to prevent flexibility when needed.

I like this story in that it's a bit of coworkers policing themselves a bit. We have a similar situation in my workplace, where smartcard authentication is used. We're all taught to pull our cards when we get up from our desks, and this is followed pretty well. The odd email has gone out under someone else's name (usually with accompanying embarrassing text) but more often than not, we'll simply pull that person's card, hold onto it, and then enjoy the few minutes of panic as they try to determine if they lost it or not. Both the customer and the security officer are none too pleased when cards go missing, so it serves as a good reminder.

Long story short, watch and remind one another frequently of good security practices, and encourage others to as well. You may think you're being a jerk at first, but as more catch on and not only adhere, but help encourage those rules, it'll be less uncool to call them out and more uncool to deviate from them.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: