top | item 45728981

(no title)

cwsx | 4 months ago

Obligatory xkcd

https://xkcd.com/538/

discuss

order

tonyhart7|4 months ago

please stop mention this anymore, I gonna crazy

atoav|4 months ago

Why? There are actually valuable takeaways from this.

One would be that people are the weak point in your security system. If all your organizational security hinges on one guy not folding, that guy is the natural target. Whether a literal 5$ wrench is used or they bribe him makes no difference.

That means you could consider shaping your org in a way that is resistent against this by e.g. decentralizing secrets. That means instead of bringing a "5$ wrench" to one person (which may even work without raising suspicion), you now need to convince multiple people at once which is much more unlikely to work without being detected.

maybewhenthesun|4 months ago

Please mention/link it even more. All security nerds _need_ to see this comic once a month.

hrimfaxi|4 months ago

I thought maybe cwsx was posting this often but that doesn't seem to be the case. Is it that that xkcd is basically a HN trope at this point?