5 ms·
I mean, i am not agreeing with Yahoo here... but isn't that a reasonable thing to do? Every act of securing or ensuring quality has a cost, and there is a line
by fizzbatter 10y ago
I mean, i am not agreeing with Yahoo here... but isn't that a reasonable thing to do?
Every act of securing or ensuring quality has a cost, and there is a line. I think most of us would agree that the line is very broken currently, but it appears you're citing a problem with the line in general, not the location of said line.
Everything has a cost, from a recall to better security to even a human life, the debate should be what we think should be paid, not whether or not we should worry about costs at all.
(If i misunderstood your intent, apologies)
- nkassis 10y agoI also agree with this, security is always in a balancing act with convenience. Yahoo fell to far into the convenience side on this one but that debate on security vs convenience is happening in everywhere. The issue I've seen is that many companies are bad at doing risk analysis about these choices. That's the bigger issue in my view.
- Diederich 10y ago> security is always in a balancing act with convenience I don't think that's always the case. A whole lot of security can be had with little or no inconvenience, given an appropriate mindset, though one might argue that such a mindset is an inconvenience in itself. :) > many companies are bad at doing risk analysis about these choices Amen to that! I think that having a basic, security aware mindset goes a long way, even if there is very little 'budget' or 'ability' to do inconvenient things.
- dsacco 10y agoPhilosophically speaking, you cannot improve security without sacrificing usability. What I mean by usability is the capability for someone to do something, not simply convenience for the users themselves. No amount of security can be added without a concurrent decrease in usability, even if that usability is something you didn't expect or want to do. For example, the user might not see a capability decrease if you use MD5 or bcrypt, but you certainly see a capability decrease because you can no longer see their passwords and you have to do extra work to maintain them securely. Sometimes security decisions are easy, like hashing passwords, because these days no one wants that capability. But sometimes they are not easy decisions. You can pass a lot of convenience savings on to users by assuming the capability sacrifice yourself (for example, choosing the password hashing algorithm behind the scenes), but you can't do this for everything (for example, mandating two-factor authentication or password resets be masse). This might come across as pedantic, but it's very important to maintain a mental model this way because it helps you understand risk analysis for more complicated security and usability tradeoffs. Starting from the premise that you can have any security without a decrease in usability is not helpful in that regard.
- jerf 10y agoYour argument is assuming something that I don't believe is true, which is that we're already on the Pareto optimality frontier for security/convenience. It is certainly true that you can not forever increase security without eventually impacting usability, but I don't think many people are actually in that position. I've improved a lot of real-world security by replacing functions that bash together strings to produce HTML with code that uses functions to correctly generate HTML, and the resulting code is often shorter, easier to understand, easier to maintain, and would actually have been easier to write that way in the first place given how much of the function was busy with tracking whether we've added an attribute to this tag yet and a melange of encoding styles haphazardly applied. What costs you can still come up with ("someone had to create the library, you have to learn to use it") are generally trivial enough to be ignored by comparison, because the costs can be recovered in a single-digit number of uses.
- nkassis 10y ago"Your argument is assuming something that I don't believe is true, which is that we're already on the Pareto optimality frontier for security/convenience. It is certainly true that you can not forever increase security without eventually impacting usability, but I don't think many people are actually in that position" That's true that we aren't at the sweet spot yet but that what I meant by companies being bad about doing the risk analysis judgement of security versus usability. On you second point languages have gone through that cycle. Look at Java doing boundary checks. That helps avoid a whole class of security issues but at the cost of making things that C was able to do easily more difficult. These tradeoffs happen at every layer.
- schoen 10y ago> No amount of security can be added without a concurrent decrease in usability, even if that usability is something you didn't expect or want to do. It seems strange to describe this this way for something like fixing a memory corruption bug or switching from a vulnerable cryptographic algorithm to a less vulnerable one. The capability that you're giving up is ... potentially breaking your own security model in a way that you weren't even aware was possible?
- Jtsummers 10y agoIt is reasonable, when your estimates are good and you're honest with regulators and customers. Sometimes your estimates are off by a factor of 10. https://en.wikipedia.org/wiki/General_Motors_ignition_switch_recalls https://en.wikipedia.org/wiki/General_Motors_ignition_switch... And you kill over 100 people, lie to regulators, lie to consumers, and end up spending billions trying to rectify the situation (recalls, settling suits, fines).
- pc86 10y agoYes, using the outcome of a formula to determine your actions generally relies on the formula being accurate.
- Ntrails 10y agoWhich is why actuarial reports have around 2 pages of conclusions and 20 pages explaining the assumptions underlying them.
- DINKDINK 10y agoIt also relies on whomever is modeling the reductive, simplistic "cost model" to know the effect of all the other variables that factor into the companies success. Do these people really think that the legal/compensation costs are the only effect? How many sales did Ford miss out on because they were labeled as the "There is a known issue in this car that might kill you but until your life is worth more than a replacement part we wont repair it" car company? Did they factor in those costs into their revenue model projections? Did they factor in the sag in price point demand "Boss I wouldn't bid the same on that contract because they've shown themselves to sell a known defective product and we'll open ourselves to legal issues if one of their cars kill one of our customers we're transporting in their vehicles" Despite what an MBA will tell you, the world is more complicated that X<Y*Z
- SilasX 10y agoThere will always be things you can do that increase safety at a cost, but some of them will necessarily not be worth the effort, or you're forced to spend without bound on ever-more safety to the point that it's not worth using (and which may push people into still-riskier alternatives). >How many sales did Ford miss out on because they were labeled as the "There is a known issue in this car that might kill you but until your life is worth more than a replacement part we wont repair it" If you're turning down a company for making such a tradeoff, that's like saying "I'll buy a Ford rather than a GM because people might die in GMs." You're right that you can legitimately criticize a company for failing to include certain things as costs, but it's not fair to fault them for somehow making this inevitable tradeoff, especially in the belief that you have some alternative provider that isn't. (And example of such a cost -- that they can legitimately be expected to but don't -- would be something like "impact on general perception of risk", "impact on reputation of the car industry".) >Despite what an MBA will tell you, the world is more complicated that X<Y*Z It sounds more like you're agreeing that it's that simple, but that Z (events worthy of consideration) is not as simple as in typical models.
- imagist 10y agoThe problem here is that the people who pay the costs of security are different from the people who are hurt when security is breached.
- vkou 10y agoLoss of user trust hurts Yahoo.
- imagist 10y agoNot enough that it isn't in Yahoo's favor to take that risk (you can't argue this--this is what happened).
- SilasX 10y agoMaybe the long-run solution is to make the coupling explicit: publicly post the value the company places on an account not being breached. (Ideally, this would work in tandem with some insurance policy that pays out for that amount, to validate that they really do so value it.) Then, you can choose the provider with a high enough value to make you feel comfortable, in the understanding that higher-valued accounts will cost more.
- coredog64 10y agoThis would work in many more contexts: The window sticker on my car can include the value they placed on passengers' lives when making cost-benefit trade offs.
- edanm 10y agoAnd who are you to decide that that isn't a legitimate decision made by the users? If people cared more about security, they'd move away from Yahoo after something like this, and Yahoo would be more incentivized to keep this from happening. Your problem is that you disagree with other users - but that's totally legitimate, not everyone has to care about the same things you care about.
- draw_down 10y agoThe point is that not ensuring security also has a cost, one which is harder to see.