Comparing Expert and Non-expert Security Practices

On 18 October 2015 at 17:13, Hector <gtalist@bell.net> wrote:
Hi all, thought to share. A little bit old but according to it.. using Linux is in the top 10 things to do to stay safe online :p yay.
Any of you follow any particular order?
https://www.usenix.org/system/files/conference/soups2015/soups15-paper-ion.p...
Hector
The reasons WHY the various practices are/are not effective are pretty interesting. The differences described between "expert" and "nonexpert" are pretty interesting too. A place worth going is to explore *why* a password manager is good to use. (Actually, that's probably a good topic for a talk. Anybody got experience with the gamut of password managers running on Linux???) Non-expert users have little faith in password managers, seemingly because they don't understand with any depth how they would be secure. This takes me back to university; we had a module in my Management Accounting #1 course on Linear Programming... It was kinda neat, and, as someone that has studied the math behind it, I'd wish I could use LP for solving some management accounting problems. But the typical management accounting student (as well as, as it happens, our instructor!) doesn't have any idea why linear programming works, with the consequence that, in industry, nobody's prepared to entrust anything to it. It's not a leap to see common application there... If the mechanism seems "too magical," to the point that it's difficult to have any intuition about how it functions, it's tough to trust it. An interesting *new* thing is the fact that we now have some new platforms with fresher behaviours vis-a-vis upgradability. And I'm not sure it helps teach better lessons. I can commonly press a button and upgrade the apps on my Android mobile phone, which ought to be better than the creaky upgrading of Windows and Windows apps, right??? Sometimes there's the right lesson. Alas, sometimes (iOS 9.0.2, I'm looking at you!!!) the upgrades include downgrades of functionality, leading users to the horrid conclusion that they shouldn't trust vendor upgrades to be improvements. -- When confronted by a difficult problem, solve it by reducing it to the question, "How would the Lone Ranger handle this?"

On 10/18/2015 09:42 PM, Christopher Browne wrote:
Alas, sometimes (iOS 9.0.2, I'm looking at you!!!) the upgrades include downgrades of functionality, leading users to the horrid conclusion that they shouldn't trust vendor upgrades to be improvements.
When confronted by a difficult problem, solve it by reducing it to the question, "How would the Lone Ranger handle this?"
I don't remember him having an iPhone. ;-)

On Sun, Oct 18, 2015 at 05:13:53PM -0400, Hector wrote:
<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><style> body { font-family: "Calibri","Slate Pro",sans-serif,"sans-serif"; color:#262626 }</style> </head> <body lang="en-GB"><div><br></div><div>Hi all, thought to share. A little bit old but according to it.. using Linux is in the top 10 things to do to stay safe online :p yay.</div><div><br></div><div>Any of you follow any particular order?<span style="font-family: Calibri, 'Slate Pro', sans-serif, sans-serif;"></span></div><div><br></div><div></div>https://www.usenix.org/system/files/conference/soups2015/soups15-paper-ion.pdf<div><br></div><div>Hector</div></body></html>
It would help if you remembered to tell your blackberry to do plain text each time you mail the list. Not easy to remember to do each time though. And no, there is no way to make that the default for a specific address (or in general), even though that would be great. -- Len Sorensen

Thanks will do :) Original Message From: Lennart Sorensen Sent: Monday, October 19, 2015 12:47 To: GTALUG Talk Reply To: GTALUG Talk Subject: Re: [GTALUG] Comparing Expert and Non-expert Security Practices On Sun, Oct 18, 2015 at 05:13:53PM -0400, Hector wrote:
<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><style> body { font-family: "Calibri","Slate Pro",sans-serif,"sans-serif"; color:#262626 }</style> </head> <body lang="en-GB"><div><br></div><div>Hi all, thought to share. A little bit old but according to it.. using Linux is in the top 10 things to do to stay safe online :p yay.</div><div><br></div><div>Any of you follow any particular order?<span style="font-family: Calibri, 'Slate Pro', sans-serif, sans-serif;"></span></div><div><br></div><div></div>https://www.usenix.org/system/files/conference/soups2015/soups15-paper-ion.pdf<div><br></div><div>Hector</div></body></html>
It would help if you remembered to tell your blackberry to do plain text each time you mail the list. Not easy to remember to do each time though. And no, there is no way to make that the default for a specific address (or in general), even though that would be great. -- Len Sorensen --- Talk Mailing List talk@gtalug.org http://gtalug.org/mailman/listinfo/talk
participants (4)
-
Christopher Browne
-
Hector
-
James Knott
-
Lennart Sorensen