Skip to content

Comment on Security for the peopleparent

Comments

I'm not so sure. "User uses the system as designed" is a huge faulty assumption -- look at all the people who put SSH private keys (or Amazon AWS keys) on GitHub or who write a shared company-wide password on a sticky note taped to their monitor. A more usable system might prevent these sorts of failure modes, or at least inform the user of the risks that result from such decisions.

I'm probably being imprecise. There's a big and important discipline of assessing the usability of a system and the impact of all the affordances the interface of a system provides. I believe that also takes a special skillset, and it's a skillset I'm happy to see new initiatives like this taking on.

I am not suggesting that security usability (or, to keep it technical, security UX) is easy, or that software security practices are necessarily good at it.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.