What people keep running into with security
Complaints tagged security, each raised by more than one person. One-off posts are not included.
23 recurring problems · 148 people · 33 forums we read
Raised more than once
Most people first.
- 27How do I know if I can DIY a repair or need a pro?Deciding whether to tackle home repairs yourself or pay a contractor comes down to guessing if the job is simple enough to figure out or risky enough to require an expert. This uncertainty often leads to second-guessing the complexity of the damage and worrying about making mistakes that make things worse.
- 25How to find a cheaper CRM when HubSpot gets too expensiveHigh-end software like HubSpot features great dashboards and lead tracking, but the pricing becomes unsustainable as soon as teams scale up users. This sudden cost jump leaves small businesses paying enterprise money just to access basic features they need.
- 13Why do Microsoft software updates and account errors break everything?Frequent, unannounced interface changes and forced cloud integrations turn routine admin tasks into hours of troubleshooting. Mysterious API errors and hidden account conflicts prevent you from finishing basic fixes, leaving you helpless when the underlying service itself is down.
- 9How to handle high-pressure roofing salespeopleRoofing salespeople often use hours-long lectures and shifting justifications — pivoting from insulation to attic wood — to push expensive, unnecessary installations like $20,000 radiant barriers. This drawn-out pressure leaves customers feeling trapped, taken advantage of, and coerced into overpaying for misrepresented services.
- 6Getting weird scam letters or emails from banks I don't usePeople are receiving physical letters and emails from unfamiliar financial companies and banks claiming missed payments or unknown inquiries using outdated personal information. This causes immediate panic and forces people to spend hours trying to figure out if their information has been compromised or if it is just a phishing scam.
- 6Where do I declare gold bullion at LAX customs?Travelers carrying high-value items like gold bullion find themselves completely baffled by confusing regulations and a lack of clear instructions on how to legally declare their assets. This administrative maze forces people to spend more time complying with bureaucracy than doing business, leading some to halt international shipping altogether.
- 6Why are security warning emails so vague?Security notifications often fail to provide specific error details or pinpoint where an issue originates, leaving teams unable to determine if their organization is actually affected. Without actionable information, administrators are forced to manually audit logs and guess whether the warnings apply to production instances or forgotten sandboxes.
- 5Tenant taking other people's packages in the buildingResidents or neighbors are walking away with deliveries left sitting in common areas, making it impossible to rely on lobby drop-offs. When another tenant takes the items, property managers are left reviewing security footage and sorting through delivery receipts to track down the missing parcels.
- 5Antivirus blocking legitimate software updates and installersSecurity software frequently flags valid installer downloads and software updates as false positives like Trojan:Script/Wacatac.C!ml and immediately quarantines them. This disrupts the patching process, blocks file downloads, and interferes with client updates.
- 5How to set up MFA backup methods so you don't get locked outLosing a primary mobile device often locks people out of their accounts because they have no configured backup authentication method or bypass option. Without a pre-established alternative, individuals are forced to file tedious IT support tickets just to re-establish access on a new device.
- 5How to use AI for accounting without breaking client confidentialityPasting sensitive trial balances and client data directly into public AI tools violates firm policies and engagement letters. Accountants need secure, siloed workflows that prevent confidential information from being exposed to external language models during technical work.
- 4Client sent me code to run locally is it malware?Malicious actors on freelance platforms and LinkedIn trick developers into executing obfuscated code, repos, or installation scripts under the guise of project testing. This exposes local machines to compromise and prevents safe evaluation of client-provided repositories.
- 4Why are automated bot attacks and hacking attempts suddenly surging?Sites on platforms like WordPress and Shopify are being overwhelmed by relentless daily bot attacks and scripts like wp2shell that exploit unmaintained pages and checkout links. This constant barrage prevents small business owners from operating normally, forcing them to spend money on services like Cloudflare while leaving them vulnerable to site cloning and identity theft.
- 4How to verify if a system was compromised after applying a zero-day patchApplying an emergency hotfix closes the known vulnerability, but it does not confirm whether the system was already breached or remains reachable from the outside. Relying on the patch installation alone as the finish line leaves administrators unable to verify what an outsider can still see and access on the box.
- 4Why can't I trust AI agents with production tasks?Autonomous AI tools remain too unreliable for critical operational workflows, forcing engineers to restrict them to basic read-only queries like code searches. This lack of reliability prevents system administrators from safely delegating routine automation or granting write access to production environments.
- 3Why does software installation fail on secure systems?Strict security controls and application whitelisting block legitimate software deployments and routine updates, forcing engineers to wait hours or days for approval. This delay doubles system commissioning times and leaves users stranded without necessary tools on weekends.
- 3How to make offsite immutable backups affordable and recoverableImmutable offsite backups protect against full compromises, but keeping them affordable often results in slow, painful restores that depend entirely on internet bandwidth. This forces teams to rely on local copies for large multi-terabyte servers just to avoid crippling recovery times.
- 3How to catch all account dependencies during user offboardingStandard offboarding catches email and licenses, but misses hidden dependencies like Power Apps, custom flows, and SharePoint ownership tied to the departing account. This leaves administrators manually digging through every admin center to prevent broken workflows and orphaned assets.
- 3How to stop an email spam bomb attacking a user inboxAn ongoing email spam bomb floods a user's inbox with hundreds of random newsletter and phishing messages a day in multiple languages. This relentless wave buries legitimate communications and overwhelms standard inbox management, leaving administrators searching for effective filtering and mitigation strategies.
- 2How to migrate away from 1Password safelyExporting credentials from 1Password requires handling sensitive data in unencrypted plaintext CSV format, which creates major security risks during the transfer. Finding a secure alternative that allows a smooth transition without exposing master passwords or vault items stops many users from successfully switching.
Comes up alongside
Topics that keep appearing on the same problems — not topics with similar names.