5 ms·
One message I hear repeatedly from cyber security pros is their organizations claim security is critical... That its, until you show them the price tag. So lon
by YCode 9y ago
One message I hear repeatedly from cyber security pros is their organizations claim security is critical... That its, until you show them the price tag.
So long as they aren't willing to resource to security and they aren't held accountable for breaches this trend will basically continue.
- ksk 9y agoYes, security is a practical reality and firms should be spending more on it. But I don't quite understand the victim blaming. Why should a company that gets attacked be held accountable?
- deleted 9y ago[deleted]
- Eridrus 9y agoBecause their negligence results in harm's to entities other than the company. Often to the firm's customers, either because the firm directly lost control of private data or because their customers got hacked through their software.
- ksk 9y agoI don't follow. Are you saying that a company should be blamed for flaws in products which they simply purchased?
- milesrout 9y agoIf you provide a product or service to your customers you are entirely responsible for it. If I buy a laptop and it craps out I don't send it back to the manufacturer, I take it back to the retailer.
- ksk 9y agoOkay, but a service and product has a warranty, and most software comes with a limited warranty allowing you to return it so I'm not sure what you mean. If Apache has a 0-day, what you want the bank to do about it if their website gets hacked?
- milesrout 9y ago>Okay, but a service and product has a warranty, and most software comes with a limited warranty Products have warranties, but this isn't really what I'm talking about. That was just an example of who is responsible: the person that you deal with is responsible. You buy a product or a service? The person you bought it from is 100% responsible. >If Apache has a 0-day, what you want the bank to do about it if their website gets hacked? The bank shouldn't be relying on software that it can't be sure is secure. If it's using Apache, and Apache has a 0-day, that shouldn't let people get all the way into their cluster and then into all their systems. They should have security in depth. The bank is responsible for the security of their customers' data. If they rely on Apache, an open source software product that they have put no funding into, have no security checked, have not audited and have not actually put any real effort into securing, then that's their responsibility. If they don't want to be susceptible to Apache 0-day vulnerabilities, they should figure out what they need to do to not be susceptible to a 0-day. That's their problem, not mine. Never mine. Always theirs. That's how responsibility works. That's how it's always worked. If a lawyer provides poor legal advice because a contracted investigator got something wrong, the responsibility lies with the lawyer.
- ksk 9y ago>You buy a product or a service? The person you bought it from is 100% responsible. They are only responsible to the extent that their contract with you allows for. Taking the example of safety deposit boxes, banks will make you sign a contract that removes liability, except in the case of gross negligence. What constitutes gross negligence is up to a court to decide. Applying that to being the victim of a cyber-attack or robbery, I don't recall a court ever not siding with a bank. Of course I don't know every single case, but maybe you can dig one up, since you seem quite motivated here.
- borplk 9y agoYep. This is generally true in business about a lot of things and especially in software because of the virtual nature of things it creates an incentive for people to pretend things and inflate their claims so they get put in the same bucket as the big guys. That's how you end up with a weak site run by 2 people on a shared hosting with outdated software but they put up a polished home-page with "military-grade 256-bit encryption" on it and a lock icon and a chunk of people will not know better. I'm sure there's a proper term in economic theory for this concept someone can point out. No one says "security of our users is our 158th priority". However their behaviour very clearly shows it. They just want the benefits of a perception of security without actually putting in the effort. And when the chances of getting punished for it is low enough they can get away with it. This attitude also creates opportunity for a certain class of employees/contractors to shine. The type that does a very shallow job but claims that "everything is done". Business people love that and think that person is so smart and effective. Want backups? No problem he'll drop a single line in a cron file to generate unverified nightly backups sitting in /var/backups and says "I have taken care of backups." in 20 minutes. Chances are nothing goes wrong for years and he'll be the super efficient hero. But it's also possible that the business will suffer catastrophic data loss and finds out the true cost of their decisions. The person who wants to tackle the problem more deeply gets punished because they think he/she is too slow or makes things complicated. It can get pretty frustrating because what happens is you end up getting asked to achieve something and when you attempt to do it people will be like "no no no we didn't mean like that ... can't you just install a security plugin or something in there in an afternoon and move on to the next task?". So you will be forced to do it in a way that is not effective/full-proof and when things go bad you still have to take the blame because it was your responsibility. At some point I started calling people out on it.