Why the hell does a financial analytics and monitoring program need to store authentication tokens to a storage system for company documents?!

#Cybersecurity people are talking about hyper-paranoid zero-trust remote-attestation stuff, meanwhile companies are doing ridiculous crap like this.

Dear #infosec community: you know how the A-10 engineers were focused on armoring the parts of the plane that were actually getting hit and actually killing the plane? Maybe do the equivalent of that here.

Side note: the whole idea of making devices say “I'm not compromised, pinky promise” and calling that a #security measure is patently absurd. Please stop.

Or at least come up with a solid explanation of why this idea isn't ridiculous. Because, speaking as someone with a pretty good understanding of how computers work, it looks ridiculous.

#cybersecurity #infosec #securityTheater #ZeroTrust