‘Security Fatigue’ Can Cause Computer Users to Feel Hopeless and Act Recklessly
nist.gov
nist.gov
I should worry about Google knowing this and that about me, I should worry about the stupid retargeting and the fact that if I do something online, it follows me through the web with banners and "youtube recommendations". And that everything is saved and googlable and everyone can know everything about me.
And I used to be worried, but now, I gave up. The assault of the security sucking companies is too high - Facebook and Google has the best engineers and everyone loves their open source code - and it's just way too convenient.
Sorry for unrelated ranting.
Exactly, it would be good if there was some relevant research about the how perception of privacy issues influences users behaviour, in relation to businesses (e.g. Google, Facebook) and state actors (governments).
The linked article explains that security fatigue has a cost on the economy; maybe if there was a similar conclusion about "privacy fatigue", that could lead to a healthy debate and, ultimately, (I know, I'm dreaming here) better privacy laws.
A pfSense VPN VM can make self-hosted services and filtering available to mobile devices and laptops. After turning off iCloud and other settings, iOS is reasonably respectful of user policy and informed consent. A one-time admin cost per year (iOS major version lifetime).
Do you plan on staying in one location, using the same IP address, for the rest of your life?
If not, then gmail will occasionally force you to use your phone number to "verify" that it's you. Of course, in fact what they really want to confirm is the association between your email and your phone.
This just happened to me a few days ago. I flew out of town. I logged in from a different city, Google forced me to verify by sending an SMS to my phone.
Dear devs, sales managers etc.: if your user made a decision respect it and not try to ask him directly if he had changed his mind every single time he uses your product, you have other tools to do that rather than yet another page which I always click "Nope" on it.
I would hope Apple would make an app ask permission before grabbing my email address from my contact card, and I have no idea how it could get this information from the Uber app.
Google is doing this with their apps - sign into the gmail app on your iphone, and chrome, maps and youtube will ask you repeatedly to sign in using the same creds.
..and looks like it's not limited to same dev. Niantic published apps are also able to pull out my Google creds. Might be because I have a google account defined in iOS, might be because they're a former-Goog company and Goog have given them backdoor details.
Any devs on iOS able to shed any real light on my vague speculation?
Here is a link about this in the context of sharing data between apps and app extensions: https://developer.apple.com/library/content/documentation/Ge...
And I accept that a high enough ranking employee at these companies can view this information at will. And that the US government has a copy of all this data too.
Otherwise, those who do use Tor or other anonymity techniques will be targeted.
At a huge number of companies, every junior dev on their first day of work gets full access to production database servers. The reality is that once you make any piece of information available to any web server, assume it can be found in anyone's hands within an hour.
That's the reality. The secret is to not care, and live life not worrying about it.
I wonder what it's like at Facebook, Twitter, Snapchat, etc.
Smaller companies never invest the time to set up proper staging and developer environments that operate on purely fictional data. It always starts as a copy of production; and the majority of companies don't even take the most basic step of swapping out sensitive info. The numbers of times I've seen users' plaintext account passwords (another problem entirely) synced to every developer's machine is honestly astounding.
Having worked at multiple of the largest, I would say your statement is 'broadly true' (especially in terms of intent, there is certainly the mission to protect that data) but there are enough edge cases that one can logically worry; Imagine a scenario where some legacy property that is in the prod vnets and needs prod access but doesn't have all the oversight mechanisms new services do, and is now handed to a very junior engineer to maintain with all the power that entails. I'm staying very far away from making any statements about opinions on the actual enterprises goals/merits from data collection to distract my key statement, but regardless of that, there are enough of these "edge cases" that I as a consumer would reasonably want to limit as much as possible the footprint of data I allow to these companies. The "vulnerable surface" of data across all of these large companies is just too wide to protect 100%, especially given that you HAVE to trust some people as "good actors", and while this tradeoff is fine for many people, I fall on the line of not being a fan.
I may be being paranoid about this, but I want to both disclose that I'm an MSFtie and none of these statements are specific or represent concrete information about any companies for which I am bound to an NDA on internal operations. They are just my learnings/intuitions as a paranoid dev/ops who has seen a wide range of operating environment and the various pitfalls within, and would have made an equivalent statement earlier in my career prior to my bigCo phase extrapolating from small/midCo patterns and trends.
On mobile, I turn off location, but I use Gmail and Android and Google search and I can't pretend I actually have any privacy left. Realistically, I don't see a way out worth taking.
And here I am preaching the value of privacy, but that's not the same as being able to make it happen.
Sort of a cold comfort, I know.
Now imagine them selling this data to the highest bidders. Insurance will know if you sport or not, if you eat healthy, if you smoke, etc.. Other companies will spring up that buy data to check if you were really sick for work, or just slacking (and businesses then buy this service for a price). Advertisers would sell their kids, mother and grandmother's soul for access to this kind of data. You think impulse-buy-optimization of supermarkets is bad? oh boy..
So yeah, fight the good fight, even if its a bit of a hassle, and slightly more expensive. You can actually find a good balance between privacy and usability. I use Protonmail for my mail, Apple Maps for my mapping needs (Google Maps as backup, sparingly), DuckDuckGo for search, Lastpass for passwords and iOS (Android is mined HARD by Google) + OS X as my OSes. Linux is even better, but you're constantly tweaking or fixing small things.
A bit of a moot point, because Google not selling it is their business model. What Google might start selling pretty soon are predictions about people (and in some way they already do it) - but never the underlying data.
If Google starts failing, then I'd become really worried though. If they're desperate enough they might just sell the data off (at their own loss of course, but a business fighting for survival will go to any lengths possible...)
1. Day to day use of data. (Google does pretty well here).
2. Collapse/failure behavior. (Will they sell it? If not, will they securely delete it as they close up shop?)
3. Breach risk. (Heartbleed was bad news, but Google is no worse than anyone.)
4. Abuse risk. (Police databases might have noble motives, but people keep stalking exes with them.)
5. Government access. (Ugh.)
Google's data ownership does better on that checklist than most people, but no one offers full safety with that list.
The best way to "fight" would be to make alternatives to Google and Facebook. You're not gonna sway the masses any other way,
Typing something into your browser's address bar (which defaults to Google's search on every platform) remains the most convenient way to find something online. For the vast majority of people, Google effectively IS the internet.
It's worse than that. I determined early on in that game that just concealing stuff could be an identifier or profile in itself. The apathy of the crowds, little oligopolies that form in browsers/apps to make them more alike, and creative ways outliers try to be different combine to increase the odds outliers get identified given certain amount of data.
The original way I figured it out was when I was working on deployment strategies for both high-assurance SSL and Tor appliances. They HW/SW architecture should've made them immune to code injection with some protection against leaks. Sounds great right? Wrong. They'd be about the only nodes where the 0-days NSA et al likely had wouldn't work. That would instantly identify them as using the strong stuff. Low volume & niche offering means small enough for close inspection. Few that mattered to enemy would be so low in number so as to be easily targeted with other more personal attacks. Just being bulletproof was itself an identifier that led to them using something better than digital bullets.
Any solutions devolved from the strong security I could prove to a large degree to a cat and mouse game like others were playing but for different objectives. Seems a bit hopeless. Even software immune to hacks has to blend in if you're wanting privacy or dodging attention of nation states. So, the widely deployed stuff also needs that property at least for whatever components you're blending with. Didn't leave me optimistic...
Another obnoxious thing is sites that, when you change your password, don't let you use one you've used in the last X months.
In both these cases, what happens is that you defeat people's attempts to make their passwords adhere to some system they can remember. And then they just says "f*ck it" and do really easy to guess passwords.
Specifically there's a good doc. from CESG in the UK https://www.gov.uk/government/uploads/system/uploads/attachm... which has a far more realistic approach to good password security.
While I think passwords are one of the biggest points of failure of modern security, seems like this would alleviate authentication policy fatigue.
We have lists of known passwords. Virtually anything up to 8 characters. Many things above that.
There are lists of millions of real-life passwords dumped from services. All of those should be used to screen passwords on entry (directly or by hash) and force a password update on match. It's reached the point that this should be mandated by law.
I know far too many nontechnical people still using utterly broken passwords (and who've had multiple accounts hacked, and insist that they're doing nothing wrong....)
Yeah, thanks for telling an attacker that they have guessed my password for a bunch of sites. Assholes.
Passwords must contain a mixture of upper and lower case letters as well as one letter and one special character
Length between 7 and 33 characters
Not the same as the previous 12 passwords
The same character cannot be used consecutively
Avoid sequential letters and numbers (123 or abc). I think this used to be enforced, not sure if it still is.
May not be the same as the name, userid or clientid. As I recall this is enforced by very aggressively with innocent passwords being rejected because they happen to have some matching substring.
https://www.fnb.co.za/demos/reset-username-and-password-PC.h... (rules are on the 5th screen in their demo)
I've been using the same password for 3 years because changing passwords is so brutal. Complaining is futile because of the bullshit cargo culting around security.
I've never understood why sites limit password length. You're (hopefully) hashing it anyways; the length of what the user enters has no bearing on what you're storing in your database.
What if they upload a GB or TB binary as password? I've always wondered but nobody told me if there's some inherent cut-off that would prevent such a DoS attack.
Doesn't that drastically lower the number of attempts required to exhaustive-search a password from a hash? Especially if people are using passwords as short as 7 characters. Even if not, that's one of the most moronic password rules I have heard.
There are a lot of smartphone apps that almost never log you out and would benefit from this. I recently had some trouble trying to remember how to log into the Taco Bell app after a session that lasted ~2 years. And I've lost count of how many friends have been unable to remember their Snapchat password and just creating a new account instead when they get a new phone.
You can change your password five times in a day though :D
You forgot to mention the kicker: after hurling 14 different password requirements at you, they let you reset your password only by answering “security” questions which are usually fixed and not even applicable. Seriously, some of the questions are so ridiculous, I have seen fixed lists where NONE of the questions applies to me. Which is OK because it’s insecure to answer truthfully anyway; I end up creating keychain items just to store the answers to my “security” questions.
My bank, with its eight different password rules, security image, and reset questions, will (and has) roll over for every breach that comes along.
The safest course is to assume that if it's connected to the Internet, it's not secure.
Secure vs. not secure is not a black and white thing.
This isn't some situation that is unique to me. Most anyone could have their life messed up badly if someone got on their email and wanted to do them harm.
And yet, the black hats who breach such systems often have an attitude like "Wow, such a reputable organization has such sorry security. They deserve what I did to them".
Computer security is a black hole that will consume ever increasing amounts of money, memory, and cpu cycles, forever. What a waste.
That is defeatist and false. Computer security done intelligently can raise the cost of an attack above the value of what is being protected.
Once you start prioritizing it with money on security vs product/system engineering, security starts turning into a money monster that delivers nothing. I've seen it happen time and time again.
The asymmetric nature of raising the cost for an attacker is a red herring. You can pat yourself on the back that you've supposedly made it 100x more expensive to attack you, but one operational fuckup pops that fantasy bubble at any time.
Not to forget the many, many instances where security systems actively harmed / enabled attacks.
Security isn't some orthogonal concern that can be developed or managed independently.
The technical problem is that we should be ruthlessly eradicating undefined behavior at all levels of our hardware and software stacks, and to the extent possible constructing applications out of building blocks that are very difficult to misuse. Among other things, this means not writing software in C or C++, which is a hard sell to a lot of people (especially if they're writing operating systems).
The economic problem is that it's nearly impossible for a customer to know whether a product is secure or not. If secure products are more expensive to produce than insecure products and customers are not willing to pay more for secure products, the result is that insecure products will be more successful. (See George Ackerloff, The Market for Lemons.)
It all depends on your threat model, so who's going to attack you and what vectors and resources they'll have at their disposal.
Sure against nation state level attackers it's fair to say that no-one but the most well funded of groups will be able to entirely avoid compromise, but it's definitely possible to avoid most of the lower end attacks that are more realistically a likelihood for most Internet users.
The assumption that nothing is 100% secure shouldn't lead to people just giving up , but hopefully lead to them spending effort on detecting attempted and successful intrusions and in having effective responses to them.
Unfortunately, the parties that need this most are the least likely to implement it. The usual response to a question whether or not intrusion detection or exfiltration dectection / prevention measures are installed is 'What?', which I find a much more scary answer than 'No.'.
So there's a tendency to downplay those requirements (what OS or application vendor is going to say "hey you should deploy something for when our security fails on you")
Irony: Every government wants to authorize hacking at the state level, but nobody is rushing to secure their own infrastructure from being hacked.
What's the point?
That's why I user a password safe so that when that happens (at least 4 times to date), I can just shrug my shoulders and move on, resetting just that one password if I still use the site.
1. Limit the number of ~~security~~ decisions users need to make;
2. Make it simple for users to choose the right ~~security~~ action; and
3. Design for consistent decision making whenever possible.
Attempting to explain the situation in plane, simple language is a better approach in my opinion.
Can that even be defined if it completely overlaps the umbrella of "people who use computers but are not IT professionals".
One of my friend's passwords for everything is expl0r3r and has been for years because his family drove a ford explorer when he was younger.
Another buddy's password for everything is "Duncan" ... because his dog is named duncan.
Pretty much everybody else I know has their password literally stickied to the side of their monitor or sitting on their desk somewhere.
Can "Security Fatigue" really be a thing if the entire world is subject to it?
It's very unfortunate that in a kind of tragedy of the commons, each site owner just rolls out the easiest authentication options available (username/password) and then leaves the user, who's rarely equipped to handle it, to deal with the fallout of having huge numbers of logins to manage.
That was 18 years ago.
Particularly raw for Dilbert: "Squeal like a pig" is from the 1972 movie "Deliverance" and refers to a assault that was one of the most disturbing US mainstream movie scenes of the 1970s.
The only real improvement in all that time that I can think of: password managers. I almost said Single Sign On, but that comes with its own security issues.
So 2FA combines something you have (your phone) with something your phone knows.
My prediction is that this will lead to even more of a rise of walled garden style ecosystems, where this problem is at least partially managed for the user by the owner of the ecosystem.
So for example if I use iOS apps for everything I can let them handle authentication for me and use my fingerprint, which is a much much nicer user experience than remembering a load of passwords.
Of course that's not great for the open web, but this very much feels like a tragedy of the commons to me, everyone knows better security is needed, but no-one wants to be the body leading the charge as it's a really hard problem to solve.
I'm two-thirds of the way thru the comments here, and you are the first to mention this. And yet, as you say, it's a "much much" nicer experience. I've started allowing iOS apps to identify me by fingerprint, and it's a lot more pleasant to do that than to type in some crazy long password.
It's very hard for me to convince people that:
A. More than likely anything you do before you call me, is going to make it worse.
B. You can always just shut off your PC.
for (;;) alert("spam!");
Chrome will, at least, give you an option to disable the alerts if it thinks you're getting them too often, but by that point you're well into scary territory.Footnote: just tried it in Chrome, and after disabling popups I got a tab which was spinning using 100% CPU and which was completely uninteractive. I couldn't even close it using the x on the tab and I had to kill it via the Chrome task manager. Hmmm...
It's hilarious to me that this thing is still a problem when it's technically trivial to solve.
Actually I don't know if the feature was due to vimperator, firefox, or just my window manager.
Seems reasonable.
> “Years ago, you had one password to keep up with at work,” she said. “Now people are being asked to remember 25 or 30. We haven’t really thought about cybersecurity expanding and what it has done to people.”
So why not switch to using password managers and hardware tokens then?
- Be rotated every 90 days
- Can never be re-used
- Be greater than 8 characters
- Be less than 15 characters
- Contain at least one letter
- Contain at least one number
- Contain at least one special character
- Cannot contain the same character more than three times in a row
- Cannot contain any piece of the username anywhere in the password
- Must have a gematria value that is divisible by 12.
- Cannot contain an even number of consonants or vowels in months of Saturn ascending
- Have paste disabled so you need to type it.
- Disable the password manager in your browser.
And while you are at it, tell them to use a long passphrase as a master password, ignoring upper case, numbers and special characters.
I recommend them to everyone I can but still people are afraid.
All credentials under one master password? Single point of failure. You could use more passwords, but we are heading back to square one then.
Next you have to decide where to make your passwords accessible for yourself. Do you also want them on the phone? Because if you don't, it can get kinda inconvenient. On the other hand, I'm quite positive my phone has more exploitable security issues than my laptop. Same for all other devices you might use. What about devices that are shared by other people? You lock yourself out of the things for which you've opted to use the password manager, or you expose it to the security issues on the said devices.
I'd rather just have less stupid passwords to begin with. Why do most stores require an account for me to place an order? Not for my security. Forums, boards, other places.. anonymous posting without accounts works just fine, and there are ways to create a persistent identity for those who want it, without requiring it from everybody. Yet most "social" sites require accounts. Mostly not for my security.
True, that. It seems many sites insist on user accounts more for their benefit than yours - they want your email address so they can nag you towards their "funnels" for further profit opportunities, along with whatever personal and/or demographic information they can scrounge for their analytics, etc. They require you to make an account, not for your security, but merely as a premise to part you with your juicy monetisable data.
At home I have a gpg-encrypted file that's my password manager. I don't particularly trust third party password managers with my roots of trust. :-)
Frankly, if it's not something I use everyday and care about, I can't be bothered to put a strong password in it.
Bonus points for:
- Basic internet hygiene. Clear that history!
- Compartmentalization. Don't put all your eggs in one basket!
- Low footprint. Don't stand out in the crowd!
- Avoid prismware like Windows at all costs!
- Blanket encrypt everything no matter how non controversial it is!
- Throw out your smartphone! Buy all the old Nokias!
- Don't order laptops from Amazon!
Something between all your passwords are belong to us walled garden touch id scheme and tin foil hat must memorize new 20 char randomized password every 10 months setup....
It seems that answers to this problem fall into one extreme or the other, but I would personally use a solution somewhere between the two that gave me peace of mind and was convenient at the same time.
This would probably be a password manager type thing / cloud solution? Maybe open source?
Some things I'd like to see: - secure passwords where appropriate: do I need my pinterest account to be super secure? - 2 factor auth where appropriate: protect my bank accounts, etc. - tell me when there's been a breach and prompt me to change my password- who can keep track of all the times I need to change my password? - let me have a rememberable password sometimes- sometimes I need to log into something not on my personal phone / computer etc. - don't let the nsa spy on me/ my cloud account / make it harder than normal - maybe integrate with keyfobs / security hardware where appropriate
thats some stuff of the top of my head but there are so many little catches in dealing with passwords that I would be happy to pay for a product that helped me manage it in the right way.
I wonder if there are others out there that fall into this same middle ground of, secure, private, good-enough?
1) A Windows domain account
2) A GitHub account
3/4) Accounts for two separate project management web apps
5) An account for our own web app
6) An account for the payroll web app
7) An account for the HR performance appraisal web app
8) An account to register for on-site flu shots
9) An account on a project development VM
10) An account for the outsourced IT security training
And probably a few more that I forgot because I'm not in front of my password manager right now.
It also doesn't help that we have a narrative around "identity theft" that puts virtually all of the burden of a leak on the account holder, even in cases where it was unequivocally the company's security that failed.
I personally feel like people who are tech-savvy should encourage and teach everyone else to use password managers.
Oh and the passphrases for my PGP and SSH keys. Also stored in my LP vault.
Can I be bothered to care more than that? Nope.
That they 'have' to use this box for work or recreation, rather than having a curiosity that fuels learning and exploration and therefore better understanding, leads to them feeling like they're at the mercy of the machine, rather than the master of it.
Even motivated, curious people can get fatigued, bored or annoyed.
But you still probably know how to drive, pump gas, and do basic things like change a tire. You have controls that you understand for things like the radio or cruise control, and you will check the manual if you want to set the clock.
On computers people just say fuck it.
Even with curiosity, the everyday stuff that's cumbersome still feels like a tedious unnecessity. Thinks like LastPass, and ssh private keys, or even 2FA are successful because they remove the tediousness yet still somehow add value in terms of security.
Pretty much.
"How did you get so good with computers?"
"I actually try."