Comment Re: Infosec incentivized for compliance, not work (Score 0) 72
My root privileges on my workstation that I can literally pop open and reimage present absolutely zero marginal security risk.
But what if a malicious website executes malicious code from my user account?
Well then it's gonna own my box. Which will let it do what?
Hack other boxes on the LAN? Can already do that without root access.
Exflitrate business data? That doesn't require root.
Steal credentials? Stored as user read only, no root required.
Again: if the end result is I get root access either way, but I stare blankly at a web training in one path...wtf is the point?
Same point as office 365 making me find the modal popunder to click before it signs in with cached credentials anyway: CYA for some lawyer and fuck wasting everyone's time.