Skip to main content

Questions tagged [security-theater]

DO NOT USE THIS TAG AS A GENERIC SECURITY TAG!! Security theater is a term that describes security countermeasures intended to provide the feeling of improved security while doing little or nothing to actually improve security. The term was coined by computer security specialist and writer Bruce Schneier for his book Beyond Fear.

1 vote
0 answers
162 views

Is there a term for when you a particular system design might prove to have some advantages, but doesn't actually qualitatively change the potential attacks on the system and thus ends up as redundant,...
tau's user avatar
  • 417
0 votes
0 answers
45 views

I'm working with an HTTPS API that requires me to include a Signature header, the signature is calculated as codeBase64(hmacWithSha384(key, body)). I'm wondering if it provides any real-life benefits ...
hangyas's user avatar
0 votes
3 answers
213 views

If some security measure serves only to add an extremely small barrier to an attack, are there generally accepted principles for deciding whether that measure should be retained? Does defence in depth ...
benjimin's user avatar
  • 195
2 votes
2 answers
205 views

For work and other official matters, I am often forced to use websites and apps which clearly have some kind of cargo cult going on in their security department, given that they impose extremely ...
Artimithe55's user avatar
2 votes
1 answer
275 views

On some internet banking websites, I've seen some CVV input fields that seem strange to me. Here is an example: The field works as such: You can not input a CVV code using a keyboard. The numbers ...
user avatar
-1 votes
1 answer
257 views

I once heard that the author of the early NES emulator "Nesticle", clearly a very intelligent person, baffingly used some kind of exploitable "Samba" or "SMB" server ...
Arlin's user avatar
  • 1
1 vote
0 answers
180 views

Snowflake is a cloud database like Google BigQuery or Amazon Redshift. Unlike them, however, it markets a "Secure Data Sharing" feature. They go to some effort (including a full "Data ...
Seamus Abshere's user avatar
3 votes
1 answer
2k views

Every time I install Windows 10, I painstakingly go through every setting that can be found in any GUI setting for the OS, disabling everything that sounds creepy. One of the most disturbing things I'...
Panayiotis Mealing's user avatar
3 votes
1 answer
3k views

OWASP recommends setting session timeouts to minimal value possible, to minimize the time an attacker has to hijack the session: Session timeout define action window time for a user thus this window ...
gregmac's user avatar
  • 543
2 votes
0 answers
151 views

Given... a public web service with enabled SSL/TLS the web service enforces authentication using JSON Web Tokens a client on a LAN without an Internet connection a proxy on the LAN that grants point-...
Reiner Rottmann's user avatar
86 votes
6 answers
20k views

I depend on PHP CLI for all kinds of personal and (hopefully, soon) professional/mission-critical "business logic". (This could be any other language and the exact same problem would still stand; I'm ...
Paranoid Android's user avatar
14 votes
1 answer
976 views

I run a localhost-only webserver (PHP's built-in one) for all my admin panels and whatnot on my machine. I'm worried that, if any random webpage has a JavaScript snippet which makes an Ajax call to ...
ParanoidAndroid's user avatar
3 votes
1 answer
393 views

Let's say that ACME, Inc. is making closed-source software. It's closed for a reason (they don't want it leaving their building other than in compiled form). Now, they are hiring some company/person ...
Marvin the paranoid android's user avatar
77 votes
8 answers
15k views

Most answers to this question about the security of satellite internet boil down to: encrypting the message is more important than encrypting the method of transfer. However, there seems to be a lot ...
gerrit's user avatar
  • 1,920
4 votes
2 answers
294 views

As an example, the US no-fly list is commonly referred to as a security theater given that it is easy to work around. However blurring license plates when posting a picture online is not considered a ...
JonathanReez's user avatar
  • 1,044

15 30 50 per page
1
2 3 4 5
7