Don’t make your security encourage legitimate users to work around it due to pointless friction
Don’t make your security encourage legitimate users to work around it due to pointless friction
Good security measures are like this. Add sandboxes so you can let users do what they want. Add authentication so people know who they're talking to. Support security keys so people don't have to worry ad much about being phished. And so forth.
Smart security allows users to do what they need to do efficiently and safely.
This unfortunately leaves a disconnect between the people who harden (who might actually hear about issues), and the people who write. Even if the writers do hear, it won't be implemented until the next revision.
the password rules force you to choose [heuristically] guessable passwords, therefore they must be changed every 90 days. simple!
ssh keys instead of passwords are a good example of better security and more convenience (for the most common use cases).
It'd be nice if more "security improvements" came with ways to make them convenience improvements too...
Probably.