logoalt Hacker News

zkmon • today at 10:37 AM • 9 replies • view on HN

I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.

It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.


Replies

ulfbert_inc • today at 10:49 AM

You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)

➕ show 4 replies
ano-ther • today at 10:46 AM

With two people in the company, there is not a lot of room for corporate games though.

> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.

tialaramex • today at 10:49 AM

> It's tussle between two counter-acting forces at play.

It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]

➕ show 1 reply
ddosmax556 • today at 12:16 PM

It's not that hard to enable 2fa & force password manager usage. And it's not that hard to use it. In fact a pw manager alone is much more convenient than remembering passwords. The only people I know who "can't remember their passwords and are locked out" are people who don't use the pw manager and have dogs*it passwords with tiny variants they forget. They often need multiple attempts to log in anywhere. Yeah 2fa & pw manager is a tick more complicated but it's not like it take hours, it takes minutes per day. And you protect against stuff like this. No sympathy, sorry.

➕ show 2 replies
giveaccountpls • today at 2:43 PM

Sorry, if your job title implies even a smidgen of security responsibility, you deserve to be fired for "123456" as your password. The person who was an administrator would fall under this label. Besides, "If productivity is not your goal, then security is not my goal." is what results in draconic security measures, because employees can't be trusted AT ALL. I really don't understand your comment.

TehCorwiz • today at 11:45 AM

Productivity and Aesthetics could also be said to be counter acting forces. Or really anything that requires contemplation. I think the problem is in how some people define "productive". Is it productive to have significant security problems which cause more work?

kay_o • today at 10:53 AM

Touch one hardware key for every interaction then, not 123456, the hell?

tokai • today at 11:03 AM

Just because a task is hard it should never absolve anything. Guy could just have quit if he didn't want the responsibility.

➕ show 1 reply
altmanaltman • today at 10:52 AM

Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"

➕ show 2 replies