July 17th, 2024

What does “Security is our top priority” really mean?

The blog questions the validity of "Security Is Our Top Priority" in organizations, advocating for a balanced approach to security without neglecting user experience. It suggests a scoring mechanism for risk assessment.

Read original articleLink Icon
What does “Security is our top priority” really mean?

The blog post discusses the concept of "Security Is Our Top Priority" in organizations, questioning its validity and practical implications. The author highlights the limitless nature of security efforts and the trade-off with user experience. They criticize hollow marketing claims and advocate for a balanced approach to security without neglecting other aspects. The post delves into the complexity of prioritizing security measures, suggesting a scoring mechanism to assess risks and determine necessary controls. The author emphasizes the need for honesty in companies' security statements and proposes a more realistic alternative to claiming security as the top priority. Overall, the blog encourages a mature and thoughtful approach to security, acknowledging its importance while avoiding extreme positions that could hinder overall effectiveness.

Link Icon 20 comments
By @Animats - 6 months
The military has a better model of security. They protect things at different security levels.

I've spent time in the classified world. Security can be obtained, but costs are high. At the aerospace company, we estimated for bid purposes that running a project at SECRET doubled the cost. Running at levels above that became even more expensive, and much slower. You have to partition things, so that only the really critical stuff gets the most expensive protection. It's common to have a project where the project is mostly unclassified, many things are SECRET, and a very few things are at higher levels.

The military views security as time-limited. When and where the attack will start is highly classified until the attack is underway. After that, there is no secret. New weapons systems eventually get used or cancelled, after which they're less secret. The intelligence community wants to protect info forever, though.

The credit card services get this. The CVV is required to have a higher level of protection than credit card numbers or names and addresses. Banks understand separation of functions and mutual mistrust. Most computer security work doesn't think this way.

By @jjav - 6 months
Here's a true story about one instantiation of "security is our top priority". You be the judge on whether this is an extreme outlier or pretty much the norm.

I was at one company where the PM blurted out (paraphrasing, but very close) "Enough of security talk. We will put out some nice wording on our website stating that security is our top priority and our product is perfectly secure. And that's that. We will not spend a single penny beyond that on making it so-called secure."

So, that's often what companies mean when they say "security is our top priority".

(The referred PM has since had a long career at a fruit-shaped FAANG, presumably making products secure. I hope they have grown up a bit.)

By @Springtime - 6 months
> In my ideal world, companies would say "We maintain a state of the art security system [...] it is one of the most important things we work on and we spend a large amount of our effort on it."

Tbh as a consumer I'd rather a company not just give self-appraisals of security in the form of overt marketing lines but let pen tests, post-mortem analyses and such speak to their robustness/lessons they've learned. Marketing is virtually always that security is top notch regardless of realities so it's hard not to be skeptical of ordinary spiels.

It's like third-party VPN services. It's all well and good to market security but when they get breached/raided/etc and it turns out they don't hold up to the claims then it just increases one's cynicism. At least those like Mullvad from everything I've seen match their statements (no affiliation, nor do I even use it, just useful for this example).

Ed Catmull of Pixar once brought up in a talk, referring to cliched lines like "Story is the most important thing" despite various productions' output being mediocre in that regard, that once an important idea can be encapsulated into a concise statement that the statement per se can be used without fear of changing behavior. Could be said for a lot of marketing.

By @cjpearson - 6 months
Instead of Chesterton, I think Thomas Aquinas made the same point more simply: "If the highest aim of a captain were to preserve his ship, he would keep it in port forever."
By @MattPalmer1086 - 6 months
The only thing I really disagree with in the article is that security needs are opposed to a good user experience.

It is certainly true that security needs can sometimes get in the way of better UX although there is plenty of security that users never encounter. It is also true that the UX of many security designs is awful. However, it is not true to say that security requirements are opposed to good UX.

You can absolutely create good UX with good security, but it will require more effort. Improving your UX doesn't normally hurt security. In fact, having better UX can help security. Conversely, improving your security does not inevitably hurt your UX (although it certainly can if you don't give it sufficient consideration).

By @miika - 6 months
If security is top priority, to me it starts from deciding what kind of data actually needs to be stored. Then the service is designed from that perspective.

More sensitive data I need store, more I need to think about security as well (and more expensive it gets).

If it's obvious that the service doesn't have much worth of hacking for, it's already better starting point than if I know it's going to be hack attraction.

By @wkat4242 - 6 months
I think it's even simpler than the article states. For every company, profit is the top priority.
By @wofo - 6 months
> It takes guts to defend non-extremist positions, because the extremists will always have more powerful one-liners.

Thanks for that quote :)

By @catoc - 6 months
The same as “We care about your privacy”
By @another-dave - 6 months
> It sounds nice, but does this in practice mean that whenever anyone has an idea to improve security, at the expense of UX, consumer prices, etc, you still implement it? Because that is what it sounds like.

Does it sound like this? If a restaurant says that "our food is our top priority", I don't think anyone would think that means they're not going to lease a premises, buy chairs/tables, hire waiters etc.

To me, the very fact that you say something is your "_top_ priority" implies that you have other priorities.

It feels like the author is responding instead to the premise "security is our only priority".

By @jsemrau - 6 months
What I commonly see with "top priority" is that it means it's someone else's responsibility. Usually allocated to the CEO.
By @throwaway81523 - 6 months
They used to say employees were #1, then they switched to security being #1. In reality, security is #10. See:

https://i.pinimg.com/originals/71/2c/a5/712ca583647508a50606...

By @Jiro - 6 months
By @konschubert - 6 months
"Safety Third" by Mike Rowe:

https://www.youtube.com/watch?v=Km8XxRCuCho

(I don't fully agree with the message though. It's not just the user of the process that is responsible for their safety. It's mostly the designers of the process.)

By @nox101 - 6 months
Could you sue for false advertising?
By @doctor_eval - 6 months
> The needs of security are opposed to the needs of a convenient user experience. Improving one typically hurts the other.

I must be Dr Contrary tonight but this strikes me as bullshit.

SSH is more convenient that telnet. Passkeys are more convenient than passwords. TouchID and FaceID are more convenient than passwords.

In general, security is an afterthought that is inconvenient to developers to add back. But in the digital world I haven’t seen many examples of security being less convenient than the alternative.

(I am writing this from an airport and definitely do not assert that this applies to the built environment.)

By @jtwaleson - 6 months
The title was edited here by mods (I liked the original, but "BS" is a maybe a bit clickbaity?). Could it be changed to: "Security is our top priority" is meaningless. ?
By @el_burner - 6 months
Even if it weren't meaningless, what's the last time you heard someone say that when it wasn't a blatant lie?
By @whatnotests2 - 6 months
Under capitalism, anything is lucky to come second, after profit.