The one piece of advice I see more than all others, more than “keep updated”, more than “run an antivirus”, more than anything else at all is “exercise common sense.” Common sense is a misnomer.

To put it simply, if common sense by IT standards were in fact common we wouldn’t have to keep telling people to use it.

What seems like a no brainer for someone who works with computers and has experience is something that the average user might never think to do. And, honestly, that’s fine.

I also think that this “common sense” thing is a great way to blame users. “Oh, it was social engineering? Well that’s there fault, you can’t defend against that.” “Oh, the vulnerability had a patch out? It’s their fault for not updating.” “It’s their fault” is the common subtext for so much of what I see.

The simple truth is that blaming users for not knowing as much as you is stupid. It’s defeatist, it’s lazy, and it doesn’t solve anything. Users should share responsibility, never blame.

I’ll post much more about common sense and the relationship between users and security in the future.



blog comments powered by Disqus

Published

30 May 2012

Categories

Tags