Stop Hacklore?
They want to help keep people safe.
That’s a motivation I certainly support, but it’s important to be sure that your actions actually support your goal.
On the 1-Dec-2025 episode of Cybersecurity Today, host David Shipley (whom I have mentioned before) talked about a new (at that time) website called Stop Hacklore! They describe themselves as “a group of current and former CISOs and security experts” who “want to offer guidance that matches reality – advice that is proportional to both the likelihood and the potential harm of various threats, not shaped by myths or dramatic exceptions.”
Ok. That sounds good. So, what’s the problem?
I think there are several. In an open letter, dated 24-Nov-2025, the Hacklore team (which definitely includes an impressive list of signatures) identifies six pieces of “outdated advice”, which they describe as “well-intentioned but misleading”. They also say that it “consumes the limited time people have to protect themselves and diverts attention from actions that truly reduce the likelihood and impact of real compromises.”
First, trying to debunk ‘myths’ is never easy, and runs the risk of increasing the visibility of the claims you are trying to address. It’s usually more effective to promote critical thinking and clearly prioritize items which are worthy of the attention. Doing that allows you to respond to ‘what about’ questions with a variation on: ‘sure, but that’s rubbish, and here’s why’ or ‘sure, but these other items are far more important’.
Second, the ‘outdated pieces of advice’ are all questionable - to one degree or another - and can have the unwanted side-effect of causing people to discount risks that are uncommon, but still present.
I’ll comment on each item separately, then try to offer some nuance to the discussion. For reference, here they are:
Avoid public WiFi: Large-scale compromises via public WiFi are exceedingly rare today. Modern products use encryption technologies to protect your traffic even on open networks, and operating systems and browsers now warn users about untrusted connections. Personal VPN services offer little additional security or privacy benefit for most people and don’t stop the most common attacks.
Never scan QR codes: There is no evidence of widespread crime originating from QR-code scanning itself. The true risk is social engineering scams, which is mitigated by existing browser and OS protections, and by being cautious about the information you give any website.
Never charge devices from public USB ports: There are no verified cases of “juice jacking” in the wild affecting everyday users. Modern devices prompt before enabling data transfer, default to restricted charging modes, and authenticate connected accessories.
Turn off Bluetooth and NFC: Wireless exploits in the wild are extraordinarily rare and typically require specialized hardware, physical proximity, and unpatched devices. Modern phones and laptops isolate these components and require user consent for pairing.
Regularly “clear cookies”: Clearing (or deleting) cookies doesn’t meaningfully improve security or stop modern tracking, which now includes identifiers and fingerprinting other than cookies.
Regularly change passwords: Frequent password changes were once common advice, but there is no evidence it reduces crime, and it often leads to weaker passwords and reuse across accounts.
My responses:
Advising people to ‘avoid public WiFi’ may no longer be as urgent or generic a warning as in the past, but that does not mean that there are no risks, nor does it mean that additional caution is not warranted. Nowadays, it is trivial to set up a new WiFi network, and – what do you know? There was a recent case of just such a thing!
QR codes are becoming extremely common, and are equivalent to clicking on a link (though arguably less secure, at least until security controls catch up). Even if there is no ‘widespread’ crime from QR-code scanning, that most certainly does NOT mean that there is no risk, and minimizing that risk by shuffling it to the operating system, browser, and ‘being cautious’ seems naive at best. Interestingly, there was a case just a few months before the publication of the letter...
What about ‘juice jacking’? To be fair, this one is probably very low risk for most people, but I think it’s reasonable to be a bit nervous about cables provided by random strangers, or charging kiosks managed by unknown parties. If you are at elevated risk of surveillance for some reason, though, maybe you SHOULD be worried...
Turning off Bluetooth and NFC is more about general hygiene and eliminating unnecessary risk. While the risk is generally low, if they’re not on, they can’t be hacked - even if some new vulnerability is identified in the relevant standard. And if you’re at elevated risk for some reason...
Clearing cookies... sigh. Sadly, I agree that this is of limited usefulness, but every bit helps. In any case, most browsers can be set to automatically block or delete cookies. For more on fingerprinting, see my post on the topic.
And finally, one I can agree with! Frequent password changes are no longer recommended, nor are traditional ‘complexity rules’. In general, the recommendation is to increase the length of passwords and use a password manager. That said, most people will not change their password unless forced anyhow, so...?
I would also note, however, that things change. As an example, the original recommendation about frequent password changes was based on opinion, and finally changed to account for the current facts. That, however, does not mean that frequent password changes might not be warranted in the future, though I would suspect that such a process would be partly- or fully-automated.
The next section, ‘Recommendations for the public’, amounts to ‘update your stuff, enable MFA, use strong passwords/passphrases, and use password managers,’ while the other sections are pretty generic and vague enough that there’s really not much there, so I won’t bother to address them.
Ultimately, I believe their goal was to help people focus their time and attention on the most urgent threats first, and that they were trying to use myths and FUD (Fear, Uncertainty, Doubt) to illustrate the fact that it’s important to have a clear understanding of the actual threats and your risk tolerance in order to prioritize effectively.
I am concerned, however, that the items they chose as examples of ‘myths’ were off-base and may well create more harm than good. The frustrating part, for me, is that they’re not wrong in stating that most of the items are comparatively low risk and that people would be better-served if they focused on other issues. I just think the approach they chose lacks nuance, and that they could have found a more effective way to address the issue.
Cheers!




Comments