upvote
I would love to hear about a world where security and productivity are not counter acting forces.

For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

If you can just create a world for that simple case, then I will rest my case.

reply
Single-sign on is actually a really obvious and familiar example where you achieved better security (now all sixty five systems we use are protected by the same security, when we upgrade that security we're upgrading all sixty five systems) and yet you got better productivity because now I can get stuff done without battling two dozen authentication systems to do it, just sign in once.

Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.

reply
Arguably, you'd still have better productivity had you not have to sign-in.

So you are still making a trade-off

reply
>Arguably, you'd still have better productivity had you not have to sign-in.

No, that is not arguable for anyone who takes more than a few seconds to think about it. Signing in has nothing to do with authentication, it's about things like "I want to have my own preferences set for showdead/noprocrast/etc. I want to maintain my own lists of favorites." Authentication & security are about making sure others don't access/alter your account or use your property or the like without permission, not about there being infinite resources and everyone being perfectly identical.

>So you are still making a trade-off

Nope.

reply
> Single-sign on is actually a really obvious and familiar example where you achieved better security

My local all-eggs basket vendor agrees 100%.

reply
All the eggs keep being stored in the same place (same computer) either way, but one gives them a deluxe padded package and the other one wraps a random material around each egg.
reply
Because deluxe padding only comes in multi-egg size, I guess.
reply
Deluxe padding is a very high quality password and/or a physical device.

You're not convincing a normal person to memorize 20 high quality passwords, and multiple physical devices are going to be put on the same keyring.

So in short, yes.

reply
>I would love to hear about a world where security and productivity are not counter acting forces.

Well, it's this one? Or at least for a wide array of practices. To take a trivial example, can you explain how switching encryption from DES to AES (a clear improvement to security) is counteractive to productivity? Of course not, whether it's AES or ChaCha20-Poly1305 or ROT13 the choice of underlying cipher is transparent to the higher level user/application. Or how about reducing memory overflow bugs? That improves security, while also reducing a certain class of crashes. How is reducing software crashes counteractive to productivity?

Even if we take your silly example you clearly intend as a gotcha:

>For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

People have to identify themselves though in a multi-user environment anyway. Even completely putting aside any sort of security, we all of course have our own preferences for work environment, our own collections of data, etc etc etc. Duh. When we access a system (be it via GUI or CLI or web site) we need to say "I want to use xyz account" anyway. So the marginal cost to auth well can be zero. Using a password manager means "entering user name" and "entering user name and password at the same time" both have the exact same cost: 1 click of a button. Or if using a smartcard/USB PIV token or the like instead, it again can be the same effort: insert it, tap something.

Certainly it's true that sometimes there are unavoidable tradeoffs. But there's a lot of low hanging fruit where things can be made more convenient/productive and more secure at the same time.

reply
You are paltering.

The premise was not to enhance security, but to design a world where security and productivity are not tradeoffs.

reply
>You are paltering.

No, I'm honestly engaging with the topic and your post, vs tossing around insults.

>The premise was not to enhance security, but to design a world where security and productivity are not tradeoffs.

And I gave you examples, including engaging with your own example/question. You claimed that "most people would certainly be more productive if they hadn't had to authenticate themselves". But IDing and authenticating are different operations, people would need to ID regardless even in a world where no security was necessary. So if the marginal cost of auth over ID is zero, then by definition that means there is no tradeoff between security and productivity. Something like a security key/card is an example of accomplishing that. Plugging that in and typing 6 numbers or touching it is not merely no extra effort vs typing my user name alone, it's literally faster.

And again to other examples, anything transparent to the user is, again, by definition not an impact on productivity. For another not merely "common" but "near universal" example, see full disk encryption (which is now often the default even with no authentication at all). FDE definitely addresses a few classes of threat scenario. What do you argue is the tradeoff in productivity?

reply
> most people would certainly be more productive if they hadn't had to authenticate themselves.

... right up to the moment when they aren't.

I like to think of a law of conservation of productivity.

Before: yours 100%, hacker's 0%.

After: yours 0%, hacker's 100%.

Nonsense, of course. Hacker's boost is nearer 100,000%.

Fact is, modern computer power is inherently far more productive for bad than good. And the economic incentive follows.

reply
Ah yes, you found the perfect argument to give sec people full and uncontrolled reign.

Not is it probable that people will take over our system. But is it possible.

reply