I've seen it before where the cybersecurity guys chase theoretical security over actual security. Mandatory password changes were a great example. In the early 2000s, they decided that forcing you to change your password every so often was a great idea. Theoretically, that was so. After all, a brute force attack on a password would eventually succeed if the password never changed. Never mind that it would take 75 years to brute force a good password policy successfully. Theoretical improvement was improvement enough. What no one seemed to understand, however, was that people would simply write a password they couldn't remember on a Post-It note and keep it on their monitor. So a small theoretical improvement led to a colossal real world disimprovement. In my office at a Fortune 500 bank in a large downtown metro area, you could go to a random desk, flip the keyboard over and find the password 40% of the time. The saddest part is that it's taken 20 years for them to figure out what a bad idea it was, and STILL people are being required to change their passwords. Dumb ideas die hard.
Here again, we have a really dumb cybersecurity idea that is prompting discussion of ways to bypass security updates, install old software from un-vetted webpages and even to bypass password protection altogether. I wonder how long it will take them to realize what a stupid idea this was?