@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Creating a security feature is 1000x easier than turning on a security feature. Ask me how I know. Optional security nearly always means low volume. Evangelism doesn’t usually escape the tech people “bubble”
@RachelTobac
Rachel Tobac
3 years
In our Infosec circle we hear people talk about multi-factor authentication as if it's obvious but the reality is very different. Twitter released their numbers -- only *2.3%* of Twitter users had any MFA method enabled during this reporting period.
Tweet media one
51
300
858
11
38
191

Replies

@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
Some security people have this terrible Darwinian attitude towards user’s security “if they don’t turn on security feature x, that’s on them” nonononononononono we are supposed to make this transparent, at worst easy - for everyone.
6
12
79
@markhachman
Mark Hachman
3 years
@dwizzzleMSFT I wonder how many "real" accounts at Twitter use MFA, and how many are just alts or bots. Otherwise, though, very telling.
1
0
2
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
@markhachman Not sure, even if you took an aggressive view on bot population that number is incredibly low for its importance to basic user security.
1
0
5
@vikascb
Vikas Bhatia
3 years
@dwizzzleMSFT Agree. However sometimes I see that the security feature’s security aspect degrades experience. I would add a corollary that security feature must meet the bar to harden invisibly unless the friction added is by design & would not impact adoption
1
0
0
@dwizzzleMSFT
David Weston (DWIZZZLE)
3 years
@vikascb 100% this is the hard work - getting the "feng shui" right. to paraphrase @dinodaizovi "security is engineering"
0
0
2
@WSV_GUY
Jeff Woolsey (also on Threads as WSV_GUY) ☮️
3 years
0
0
1
@kevinriggle
Kevin Riggle
3 years
@dwizzzleMSFT You know also, like, if somebody takes over my Twitter account it’s *embarrassing*, but I’m not permanently owned like if they take over my primary email
2
1
3
@circuitloop
circuitloop
3 years
@dwizzzleMSFT I don't care about my Twitter account so much that I want to find my phone to login to it.
0
0
0
@jonasLyk
Jonas L
3 years
@dwizzzleMSFT "Creating a security feature is 1000x easier than turning on a security feature. " i totally believe you... but how about you get started some project that collect all enable/disable buttons into one app that also can show the current state of the features?IT SHOULDNT BE SO HARD
0
1
6
@RealVenky
Venky Venkateswaran
3 years
@dwizzzleMSFT Seen that movie play out before!
0
0
1
@dragondave
Dragon Dave 🐉
3 years
@dwizzzleMSFT I am 1 for 2 for getting locked out of my personal Github account because I turned on 2FA to mollify a company I was working with and lost my phone and backup codes simultaneously. Availability is a significant concern for me turning on 2FA.
1
0
1
@kjentech_
Kasper Jensen 🇩🇰
3 years
@dwizzzleMSFT Yo I respect that. However, some security features have low yield but very high barriers. There are some diminishing returns at play. 2FA will provide much better protection than a default HVCI config. Both demand much of the user, but HVCI provides little value in itself.
1
0
0