• setVeryLoud(true);@lemmy.ca
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    I literally just completed a Secure Code Warrior formation mandated by work, and one of the videos states “websites with expired certificates transit your information unencrypted, leaving you exposed to hackers” 🤦 like bruh you’re supposed to know better, you teach cybersecurity for fuck’s sake.

    • jj4211@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      22 hours ago

      I’ve met two sorts of dedicated cybersecurity experts:

      The sort that only understands how to click ‘scan’ in various tools and repeat output and browser error messages without understanding nuance. Had a fun incident where the nuance really mattered in interop with a popular product in my niche, company said we must not implement the interop because it was hopelessly insecure. When I pushed back on the nuance (folks behind the ‘vulnerable’ tech had way much more sway in the market than we did), got told I should really educate myself and read the paper on the vulnerability to understand that my proposol to workaround it was impossible. For one glorious moment in my career, I got to tell them to look at the paper again and specifically the author (I had written up the vulnerability in the first place). After a brief shock though, he still went back to even though I may have found it and explained in key detail, I still must not understand the implications…

      Then there’s those that understand and can engage in nuance, but will still say inaccurate stuff, because they’ve learned being accurate and precise with the lay person doesn’t work too well, and easier to just say “big scary” instead of explaining precisely the threat model and rationale. I will confess on a number of threads I have seen this happen and let it go without correction because correcting wouldn’t have changed the core of the material, but would make the discussion go on even longer and waste more time. I personally can’t bring myself to outright say the wrong things, but I do understand why it’s the more practical strategy sometimes.

      • setVeryLoud(true);@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        21 hours ago

        I’m the kind of 'tism where I can’t get myself to tell white lies and will argue up and down until the truth prevails… sometimes to my own detriment, but I really like to understand the underlying mechanisms and the nuance underneath things, otherwise I feel lied to, and I thusly can’t get myself to feel like I am deceiving others.

        Please share the paper, I’m curious!

        • jj4211@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          21 hours ago

          I’m trying to stay too anonymous, the paper is of super niche interest and the vulnerability comes down to a popular configuration being vulnerable, but a hardened configuration is possible, but requires randomizing some data that folks tend to leave non-random because it’s the lazier way to set that up and it wasn’t formerly recognized that the randomness of the data had security implications.

    • Kairos@lemmy.today
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      1 day ago

      Computing and by extension cybersecurity has a lot of mouth-breather idiots because it’s so new.

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        22 hours ago

        It’s not so new anymore, however, it is widely known as an “easy” way to a strong six-figure salary, so we have a lot of gold-rush mouth-breather idiots that never would have gotten into this in the first place if not for the dollar signs. Really started to turn south around the time dot-com inspired early career people to get in on the bubble.