frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Enterprise security can be messy: Building a Security-Aware Culture

2•rezliant•1h ago
Your executive team gets it. They've approved the budget, they mention security in board meetings, they understand the stakes. You're not fighting for recognition at the top anymore.

But then you look at what's actually happening three levels down. The marketing team is sharing credentials to social media accounts. Sales is pushing back on MFA because it adds seconds to their login process. Developers are storing API keys in public repositories because it's faster than the approved method. Remote employees are working from unsecured networks and don't think twice about it.

The executive commitment is there. The company-wide behavior isn't. And that gap is where breaches happen.

This is the challenge that keeps security leaders up at night. You have the mandate from above, but translating that into thousands of daily decisions made by people who have completely different priorities is a different game entirely.

Comments

necovek•58m ago
It happens because cybersecurity teams do not design for efficiency and believe that security trumps everything else. If they understood that security, just like anything else, is there to drive the business, they'd perhaps sit down with people doing the work. And then figure out how hard it is to share a simple file or a photo, take it to the print shop as one can't plug in their private USB stick, or how annoying it is to develop Linux IoT firmware on WSL, or how annoying it is to get logged out every 2h.

Because unless you do, people will adopt behaviour that makes them productive, and instead of increasing security, your policies will drive it down.

This is not a result of "bad employees": this is a result of bad security policies.

mrktf•47m ago
Yes, i couldn't agree more with this. The problem these "bad employees" earns wage by getting results and not entering multiple times mfa codes during day or repeating same logins. And talking from experience: these secure practices starting to approach at least hour of productive time everyday, which is literally robbing time
bdangubic•34m ago
No security works unless it is enforced and there are severe consequences

> Marketing team sharing credentials

Fireable offense, immediate firing first time this happens, won’t happen again after that, both of person who shared the credentials and person who used the shared credentials

> Sales MFA

Prevent login without it, let them bitch about it for a week

> API keys in repos

Fireable offense not just for commiter but entire team

tacostakohashi•32m ago
Well, that's because somewhere between the executive team, which "gets it", and "three levels down"... somewhere between 1 and 2 levels down, there is a team that translates "security" into some compulsory training, scanning internal software/apps/libraries/libraries using crappy automated vendorware, and counterproductive/arbitrary password requirements.

After that, "security" starts to mean "ticking all the boxes to keep the scan happy and stay off the report" (even if the scans are wrong, out of date, littered with false positives, and lacking the ability to find basic problems) and stops having anything to do with actually being secure.

RJ000•24m ago
"..teams not design..efficiency.."

Enough truth in that.

Need hours back and forth w/the end user, moderately sophisticated UX designers (eg. empathy, anybody?) user education (not mandates) and training, an actually useful help desk, efficient equipment... And real time graduated enforcement that impacts all levels, not just the bottom level perp-scapegoat.

At IT School with Apple Lisa

https://blisscast.wordpress.com/2024/06/04/apple-lisa-gui-wonderland-3/
1•fabiojava•19s ago•0 comments

The Whirlpool Is the Mountain

https://thinking.relica.io/the-whirlpool-is-the-mountain/
1•m-xtof•1m ago•0 comments

All recent bash commits are by one person

https://cgit.git.savannah.gnu.org/cgit/bash.git/log/
1•behnamoh•1m ago•0 comments

Ask HN: What open source projects are you grateful for?

1•jayzalowitz•2m ago•0 comments

Signal's president warns AI agents are an existential threat to messaging apps

https://fortune.com/2025/11/27/ai-agents-are-an-existential-threat-to-secure-messaging-signals-pr...
1•giuliomagnifico•4m ago•0 comments

Show HN: Hatch v1.16.0 – workspaces, dependency groups and SBOMs

https://hatch.pypa.io/1.16/blog/2025/11/24/hatch-v1160/
1•ofek•6m ago•1 comments

Why Have Vaccines Become a Religion?

https://www.midwesterndoctor.com/p/why-have-vaccines-become-a-religion
1•bilsbie•7m ago•0 comments

How Microsoft's developers are using AI

https://www.theverge.com/tech/831379/microsoft-developer-ai-usage-stats-notepad
2•manveerc•8m ago•0 comments

Major journal under fire for omitting Pfizer's failed flu data in seniors

https://blog.maryannedemasi.com/p/major-journal-under-fire-for-omitting
1•bilsbie•9m ago•0 comments

YouTube testing new 'Home' page with more control over suggested content

https://9to5google.com/2025/11/26/youtube-testing-new-home-page-with-more-control-over-suggested-...
2•geox•10m ago•0 comments

LLM unpredictability isn't a model problem – it's a process problem

https://pub.towardsai.net/uncertainty-architecture-a-modern-approach-to-designing-llm-application...
1•oddish-tv•12m ago•1 comments

Disallow code usage with a custom `clippy.toml`

https://www.schneems.com/2025/11/19/find-accidental-code-usage-with-a-custom-clippytoml/
1•austinallegro•13m ago•0 comments

Show HN: PrinceJS v1.7.7 Update. Down to 2.2 kB and top (13yo dev)

1•lilprince1218•16m ago•0 comments

Major AI conference flooded with peer reviews written by AI

https://www.nature.com/articles/d41586-025-03506-6
2•EA-3167•17m ago•0 comments

How to do Localization and Internationalization properly on the Web

https://community.qbix.com/t/how-qbix-handles-text-translation-and-international/783
1•EGreg•17m ago•1 comments

Did We Just Solve the 100-Year War Between Quantum Theory and Gravity?

https://pajuhaan.medium.com/did-we-just-solve-the-100-year-war-between-quantum-theory-and-gravity...
1•pajuhaan•20m ago•1 comments

Show HN: Cool fonts you can use almost anywhere

https://fontgen.cool/
3•liquid99•21m ago•0 comments

Cree syllabics still used today

https://www.thecanadianencyclopedia.ca/en/article/cree-syllabics
3•ilamont•25m ago•0 comments

Show HN: Zenus – A note-taking app with Local, Server and Client mode

https://github.com/skorotkiewicz/zenus
1•modinfo•25m ago•0 comments

Stochastic Bohmian Framework for Retrocausal Quantum Communication

https://github.com/DOSAYGO-STUDIO/quacomms
1•keepamovin•26m ago•0 comments

Pointer Pop Quiz

https://dave.cheney.net/2025/11/27/pointer-pop-quiz
1•todsacerdoti•27m ago•0 comments

Show HN: LLM Inference Performance Analytic Tool for Moe Models (DeepSeek/etc.)

https://github.com/kevinyuan/llm-inference-perf-model
1•kevin-2025•27m ago•0 comments

Jeff Dean on AI Trends at Stanford AI Club [video]

https://www.youtube.com/watch?v=AnTw_t21ayE
2•guiambros•29m ago•0 comments

Electron vs. Tauri

https://www.dolthub.com/blog/2025-11-13-electron-vs-tauri/
2•todsacerdoti•31m ago•0 comments

LaSuite Keynote

https://www.youtube.com/watch?v=X6c-mYOWrvA
1•maelito•32m ago•0 comments

Study: First Visualization of the Internal Structure Behind AI Decision-Making

https://news.kaist.ac.kr/site/newsen/html/news/?mode=V&mng_no=55090&skey=&sval=&list_s_date=&list...
1•giuliomagnifico•35m ago•0 comments

Desperately Seeking Squircles (2018)

https://www.figma.com/blog/desperately-seeking-squircles/
1•williamjsdavis•36m ago•0 comments

iOS games for iPads that cannot be upgraded beyond iOS 9

https://cjstewart88.github.io/vintage/
3•walterbell•36m ago•0 comments

All your LLMs ranked by speed every minute

https://metrik-dashboard.vercel.app/
2•mbouassa•37m ago•1 comments

Firm pioneers 3D printing copper coolers directly onto processors

https://www.tomshardware.com/3d-printing/firm-pioneers-3d-printing-copper-coolers-directly-onto-p...
1•Teever•38m ago•0 comments