this post was submitted on 26 Sep 2026
408 points (95.1% liked)

Technology

88348 readers
3585 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] isVeryLoud@lemmy.ca 3 points 2 days ago (2 children)

I literally just completed a Secure Code Warrior formation mandated by work, and one of the videos states "websites with expired certificates transit your information unencrypted, leaving you exposed to hackers" ๐Ÿคฆ like bruh you're supposed to know better, you teach cybersecurity for fuck's sake.

[โ€“] jj4211@lemmy.world 2 points 1 day ago (1 children)

I've met two sorts of dedicated cybersecurity experts:

The sort that only understands how to click 'scan' in various tools and repeat output and browser error messages without understanding nuance. Had a fun incident where the nuance really mattered in interop with a popular product in my niche, company said we must not implement the interop because it was hopelessly insecure. When I pushed back on the nuance (folks behind the 'vulnerable' tech had way much more sway in the market than we did), got told I should really educate myself and read the paper on the vulnerability to understand that my proposol to workaround it was impossible. For one glorious moment in my career, I got to tell them to look at the paper again and specifically the author (I had written up the vulnerability in the first place). After a brief shock though, he still went back to even though I may have found it and explained in key detail, I still must not understand the implications...

Then there's those that understand and can engage in nuance, but will still say inaccurate stuff, because they've learned being accurate and precise with the lay person doesn't work too well, and easier to just say "big scary" instead of explaining precisely the threat model and rationale. I will confess on a number of threads I have seen this happen and let it go without correction because correcting wouldn't have changed the core of the material, but would make the discussion go on even longer and waste more time. I personally can't bring myself to outright say the wrong things, but I do understand why it's the more practical strategy sometimes.

[โ€“] isVeryLoud@lemmy.ca 1 points 1 day ago (1 children)

I'm the kind of 'tism where I can't get myself to tell white lies and will argue up and down until the truth prevails... sometimes to my own detriment, but I really like to understand the underlying mechanisms and the nuance underneath things, otherwise I feel lied to, and I thusly can't get myself to feel like I am deceiving others.

Please share the paper, I'm curious!

[โ€“] jj4211@lemmy.world 2 points 1 day ago

I'm trying to stay too anonymous, the paper is of super niche interest and the vulnerability comes down to a popular configuration being vulnerable, but a hardened configuration is possible, but requires randomizing some data that folks tend to leave non-random because it's the lazier way to set that up and it wasn't formerly recognized that the randomness of the data had security implications.

[โ€“] LodeMike@lemmy.today 3 points 2 days ago* (last edited 2 days ago) (2 children)

Computing and by extension cybersecurity has a lot of mouth-breather idiots because it's so new.

[โ€“] jj4211@lemmy.world 3 points 1 day ago

It's not so new anymore, however, it is widely known as an "easy" way to a strong six-figure salary, so we have a lot of gold-rush mouth-breather idiots that never would have gotten into this in the first place if not for the dollar signs. Really started to turn south around the time dot-com inspired early career people to get in on the bubble.

[โ€“] isVeryLoud@lemmy.ca 2 points 2 days ago (1 children)

I think you a word, "cybersecurity" perhaps?

[โ€“] LodeMike@lemmy.today 2 points 2 days ago