back

by josephcsible·8mo ago·view on hn ↗
The page after completing the quiz is even worse:

> Technical Knowledge 9/8

> Consistency 1/5

> Risk Awareness 0/10

> Contradictions Identified:

> You acknowledged TLS does not protect the join phase, yet cite TLS as your primary safety reasoning

Not a contradiction. It doesn't matter that the join phase isn't protected.

> You acknowledged personal computers lack the defense in depth of corporate devices, yet advise the general public that Untrusted (Public) WiFi is safe for their personal devices

Not a contradiction, because the "defense in depth" of corporate devices isn't why public WiFi is safe for them.

> You demonstrated strong understanding of technical risks, yet advise the general public that Untrusted (Public) WiFi is safe

> Cognitive Biases Detected:

> Your responses reveal patterns of reasoning that may interfere with objective risk assessment:

Not everyone who disagrees with you is cognitively biased.

> Expertise Bias high

> You demonstrate strong technical understanding of the risks, yet advise the general public it's safe. This suggests you may be projecting your own technical capability onto others who lack your knowledge and tools to protect themselves.

No, it's because modern devices are secure against these kinds of attacks out of the box.

> Sunken Cost Fallacy high

> You understand the technical risks yet continue using public WiFi regularly and recommend it to others. This pattern suggests 'I've been doing it this way for years, so it must be okay' reasoning rather than objective risk assessment.

No, it's okay for the technical reasons I explain in the rest of this post.

> TLS Scope Misunderstanding high

> You correctly acknowledged that TLS does not protect the join phase or lower-layer attacks, yet you cite TLS as making public WiFi safe. This indicates a fundamental disconnect between your technical knowledge and your safety reasoning.

No, it's because attacks on those layers won't harm users, because everything important where they could be harmed is on the higher layers that TLS does protect.

> Assessment Capability Disconnect high

> You acknowledged that you cannot assess a network's security configuration before joining it, yet you advise the general public it's safe. How can something be 'safe' if you cannot assess whether it's configured securely?

Because it's safe for my device no matter how it's configured, since my device doesn't need to trust it to use it.

> Understanding the Tensions

> When technical knowledge and public advice diverge, it may reflect underlying tensions between competing priorities. These are common conflicts that many security professionals navigate:

> Technical Understanding vs. Professional Identity

> The Tension: You understand the technical risks, but acknowledging them publicly might undermine your professional reputation based on historical commitments to the perceived status quo of "WiFi is fine."

> May contribute to: Expertise Bias, Sunken Cost Fallacy

No, it's that you're way overblowing the technical risks. When a bunch of experts who understand the technical risks say it's okay, maybe you should step back and consider that you might be wrong, instead of throwing a list of cognitive biases at everyone who disagrees with you.

> Objective Risk Assessment vs. Personal Convenience

> The Tension: Balancing security assessment with practical convenience and personal usage patterns.

> May contribute to: Convenience Over Security, Optimism Bias

None of the quiz answers had anything to do with convenience.

> Enterprise Security Standards vs. Public Advice

> The Tension: Navigating different risk tolerances between corporate managed devices and consumer devices without enterprise controls.

> May contribute to: False Equivalence, Contradictory Risk Tolerance

As I said earlier, the enterprise controls aren't necessary for public WiFi to be safe.

> Evidence-Based Reasoning vs. Absence of Visible Harm

> The Tension: Assessing risks when direct evidence is limited and passive surveillance is undetectable.

> May contribute to: Availability Bias, Assessment Capability Disconnect

So since there's no evidence for your position, we should just assume you're right?

> Defense in Depth Philosophy vs. "TLS Solves Everything"

> The Tension: Weighing the scope of TLS protection against comprehensive network-layer security concerns.

> May contribute to: TLS Scope Misunderstanding

TLS doesn't protect literally everything, but it protects everything that's actually important for users to be able to use public networks safely.

> Resolution

> These biases resolve when you align your advice with your technical knowledge. The simplest consistent position:

Again, people disagreeing with you is not a bias!

> "If you can use a mobile hotspot, it's safer than public WiFi."

> This advice:

> Matches what corporations require for managed devices

Plenty of corporations don't require this.

> Acknowledges join-phase risks that TLS cannot mitigate

But these aren't actually problems.

> Doesn't require users to assess network security they cannot verify

Public Wi-Fi already doesn't, as I explained earlier.

> Provides a practical alternative that's readily available

Mobile hotspots are very expensive compared to public Wi-Fi.