Does making security too tight weaken overall security
This is primarily about computer security but the concept may come from
physical security. l remember hearing somewhere that if you
make entry for authorized users too complex or cumbersome, that overall
the system becomes less secure.Do you know of any formal writings on this
subject that might make good sources for an proposal or essay?
/>Here are some examples l can think of: 1.Requiring passwords that are so complex and difficult to remember.The user simply writes them on a piece of paper next to their computer. 2.Requiring a cumbersome series of authentications when logging in.The user, in their frustration, simply stops logging out and leave the machine logged in all the time. />3.Physical security example:Entry at the door takes a long time, so employees start letting coworkers in through a service entrance or side door.
Universal Access Control (UAC) in Windows Vista is another
classic example. The prompts become so frequent and annoying that the end
user simply clicks ''Allow'' to everything. Think Pavlov is dog.
Or he just disables the damn thing completely.
5 posts
• Page 1 of 1
Who is onlineUsers browsing this forum: 4 guests |