logoalt Hacker News

zaptheimpalertoday at 5:23 PM8 repliesview on HN

"Security" is just a scourge on software at this point. It means 2FA on every trivial site, being logged out every few hours for no good reason, having to fuck with settings and type "disable sandbox" to run an agent in YOLO mode which still won't work over mobile, being unable to install an unsigned extension at all in firefox (not behind a setting, literally impossible - you have to get Firefox Developer Edition), sites spamming me to get passkeys which will no doubt be declared insecure and replaced by some more moronic thing when users find a way to get hacked with those too, 80 layers of access control/service identities/IAM/Oauth to host an S3 bucket, OAuth everywhere that won't even work on a headless device, banking websites that want their own special snowflake app as 2FA instead of using TOTP, banning VPNs and slowly rolling out completely real identity surveillance on every corner of the internet to "protect the children", ban open-weight models because the numbers are going to send your data to China, and it just goes on and on and on..

When is this insanity going to stop? I really think the IT security industry ought to be ashamed of itself. Security has become a totalizing value that trumps every other value - convenience, user-friendliness, privacy, hackability, openness, just anything at all in the name of MORE SECURITY.


Replies

AnthonyMousetoday at 7:32 PM

There is a simple and highly accurate heuristic to tell if a security measure is reasonable:

Is it an open standard that anyone can permissionlessly implement?

When the answer is yes, there is a high probability that it's something reasonable, e.g. TOTP.

When the answer is no, what you will find behind the curtain is either a fool or a crook.

show 1 reply
matheusmoreiratoday at 9:03 PM

All this boils down to governments wanting security from their citizens and corporations wanting security from their customers. It's not going to stop, ever.

show 1 reply
sgttoday at 6:47 PM

Don't forget "Remember for 30 days" checkboxes that don't do anything.

jck86today at 7:29 PM

> 2FA on every trivial site

But it helps against account sharing, err I mean they make database leaks irrelevant except for private info of the customer, err I mean that we can now send more mail to the customer about new AI features without risking they think it is phishing, err I mean this is the easiest measure for the auditor findings so since we implemented this we don't need to fix all the crappy internal api auth problems and atrocious out of date dependencies, err I mean...

show 1 reply
hnlmorgtoday at 8:16 PM

IT has always been a spectrum with security at one end and convenience at the other. There is no recent trend that’s changed that. That’s just how life works.

show 2 replies
CamperBob2today at 5:27 PM

I really think the IT security industry ought to be ashamed of itself.

See Pournelle's Iron Law of Bureaucracy.

thereintoday at 7:10 PM

It is all so frustrating.

Reminds me of what Ubiquiti tried to pull a few weeks ago. They wanted to force everyone to their Cloud UI and login instead of the local interfaces so they reduced the local session lifetime to something insane like 20 minutes while lying to our faces and saying it is for security, and kept the session lifetime longer on their cloud panels. They made sure to exclude this from their changelog too.

The community started monkey patching their local scripts, wrote services to undo their changes, many people disabled auto-updates as Ubiquiti only makes their product worse with their updates. Publicly complained on their support forum that we are onto their little plot.

They ended up backtracking for now but you just know they will try again like Google does.