Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The article does talk about putting weights on the dimensions to account for different dimensions having different importance.


For one we need to start talking about taking off the weights from security dimension, because it's becoming ridiculously overemphasized for things where it frankly doesn't matter much for. All at the cost of "usability", which is a fancy word for saying people's time and effort, which is literally the only truly non-renewable, priceless resource we have.


My experience has been that security is mostly treated as some contractual obligation that has little benefit and just costs money so the minimum amount of effort that prevents charges of gross negligence is put in. But I’m glad to hear that apparently there are places that take it more seriously.


Passkeys, 2FA being deployed the more intensely the more trivial and non-critical for users a site is, mobile platforms getting absurdly locked down, naive takes on "lethal trifecta" sucking out whatever little air in AI discussions that was left by IP apologists". In the real world, everyone in this industry seems to be showing off pointing out potential vulnerabilities and security considerations in any new idea or concept that appears - as if that were something to be proud of, instead of a solemn duty that more than likely will just prevent a nice thing from existing in the first place.

From where I stand, the industry is obsessed with security, way past the point of rational thought.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: