Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Macs Need Least Privilege Too

Posted June 17, 2011    Peter McCalister

Turns out that Macs aren’t as virus and hacker proof as originally perceived. Just check out a recent posting on to read all the details.
In this blog post it appears that a new malware threat is appearing when users perform Google searches.
I’ve actually seen this malware pop up on a Mac recently, and the recommendation to mitigate this threat was to run as least privileged user (“of course”). Running as a standard user can blunt the attack and generally enhance security on any operating system. Interestingly, a post was made in the comments section below the article that got me thinking.

The commenter said, “nothing can defend against user stupidity.” If the organization allows users to run with administrator privileges on any operating system, is it really a surprise that bad things can and do happen? Is it realistic to think that users will do the right thing when faced with a security decision?

As IT professionals, it is easy to point the finger at the user and call them “stupid,” but that is because we have learned (in some cases, the hard way) to spot security threats that come from suspicious downloads and phishing scams. Further, users simply want to get their job done. If IT security is not part of their job description, it shouldn’t really come as any surprise that users ignore these security threats, which are obvious to IT professionals.

It could be argued that everyone has a responsibility when it comes to security, but that doesn’t mean that we should simply ignore recommendations to remove administrator privileges from users and call them stupid.

Leave a Reply

Additional articles


Answering the age-old question, ‘What’s plugged into my network?’

Posted October 9, 2015    Alejandro DaCosta

“What’s plugged into my network?” is a question I hear frequently from security administrators. And, really, it’s no surprise why. No longer do we have to account just for the physical servers in our datacenters, workstations and a few network devices. Now we need to keep track of roaming laptops, dynamic virtual systems, off-site cloud deployments and BYOD.


Closing the Vulnerability Gap

Posted October 7, 2015    Brian Chappell

Managing vulnerabilities is a significant challenge for many organizations. The main difficulties with managing this manifest in two key areas. The first is that the list isn’t static. The second is priority.


Scottrade Breach: Identified by Federal Officials

Posted October 5, 2015    Morey Haber

Late afternoon on October 2nd, news leaked out of another large security breach, now at Scottrade. The identity count of records, in the millions again (4.6 million is the latest). This breach comes on the second day of national CyberSecurity month, the first being Experian/T-Mobile breach.