269 karma · joined September 2, 2017
If the security concept is based on educating and teaching people how to behave it's prone to fail anyway, as there will always be that one uninformed and ignorant person like me that doesn't get the message. As soon as there is one big gaping hole in the wall, the whole fortress becomes useless (Case in point: haveibeenpwned.com) Also, good luck teaching everyone in the company how to identify a personalized phishing message crafted by ChatGPT.
For the other two arguments: I don't see how "But we solved it in my company" and "Some other departments also have safety/security-related primary KPIs" justifies that IT security should be allowed to just air-gap the company if it serves these goals.
Great that you, the IT security person, sleeps much better at night. Meanwhile, the rest of the company is super annoyed because nothing ever works without three extra rounds with the IT department. And, btw., the more annoyed people are, the more likely they are to use workarounds that undermine your IT security concept (e.g., think of the typical 'password1', 'password2', 'password3' passwords when you force users to change their password every month).
So no, good IT security does not just mean unplugging the network cable. Good IT security is invisible and unobtrusive for your users, like magic :)
At least it's not sci-fi-risk averse ;)
Wow, we really are at the point where you just need to insert "ChatGPT" into some boring random headline to make it news :)
The entitlement is called workers rights. People fought quite hard to get the ones we have right now. E.g. my grandfather was still working 6 days and 48h a week (same country as OP). Back then people also called the workers "entitled" who dared to ask for more than one free day per week.
As I see it, this movement will only be succesfully completed once people can rent your skills without also owning your body during that time.
In the real world, however, no one is usally forced to WFH. But we were forced to WFO.
Assume for a moment that working remotly and a flexible workday would have been always the default. And now some companies decide: Hey let's contractually enforce a 9 hour continuous workday where all our workers will be locked in a big ugly building that we build just for that purpose (Btw. at least one of the 9 hours will be unpaid because this is where people will have lunch. Also we won't reimburse anyone for their traveling expenses or their time spent during the commute).
Now read again the arguments you wrote to support this new idea.
The thing is, Facebook and the other social media companies have never had any real interest to support research projects that collect and analyze their data. Why should they?
However, since the public outrage over the CA event they basically have carte blanche to deny all these requests - even from seemingly credible scientists - and just say: "Hey, we just want to prevent another CA."
E.g., how about an open source spider/crawler that anyone can run on their own machine continuously contributing towards a distributed index that can be queried in a p2p fashion. (Kind of like SETI@home but for stealing back the internet).
Just think about all the great things that researchers and data scientists could do if they had access to every single public Facebook/Twitter/Instagram post.
Okayokay ... also think about what Google and FB could do if they could access any data visible to anyone (but let's just ignore that for a moment ;)