4 ms·
> It very much is a trade-off this seems like goalpost moving. first you said 'we as a society', yet there isn't much 'we' in this. it doesn't seem to me tha
by abiox 9y ago
> It very much is a trade-off
this seems like goalpost moving. first you said 'we as a society', yet there isn't much 'we' in this. it doesn't seem to me that people (the general public) are properly aware at just how vulnerable they are. they haven't therefore 'decided' that this is okay.
> the expense that would go in to making a large enterprise network reliably secure would be extreme, and would drive prices up, retard economic growth
what is this based on?
- tptacek 9y agoPart of living in a society is recognizing that you still belong to it even when it makes decisions you don't agree with. To more directly answer your question, though, consider a regime of general commercial liability for security incidents caused by failures of engineering (which Equifax is an example of). What would it be like to bring new products to market under such a regime? How much more difficult would it be to enter the field? How much more difficult to hire qualified people? What would that do to the prices of things made possible largely through software engineering work? When the prices of things increase, they're put out of reach of more consumers; markets constrict. What does that do for employment? What does reduced employment in a sector do to wages? I'm not saying this to justify insecurity. I'm ambivalent about the tradeoffs our society has made on these issues. I just don't think we tend to grapple with them honestly on HN.
- chris_wot 9y agoIf that new product exposes scads of private data, then it's rather irrelevant. These credit scores aren't something most people signed up for, they are a product for financial lenders and not for the direct consumer.
- tptacek 9y agoLike I said, the fact of the tradeoff probably does have implications for how we regulate companies like Equifax.
- Drdrdrq 9y agoSorry, I have to disagree. Performing regular pen testing is costly, so skiping it is a tradeoff. Employing a team of security engineers is also costly and there aren't enough of them to make that viable for all companies. Tradeoff. But putting such data in direct access of a web server, a single RCE away from exposure? That's not a tradeoff, that's negligence.
- tptacek 9y agoYou've lost me. I think you may have misunderstood my point about pentests. I mean "success" from the perspective of the testers: you asked me to own your network up, and I succeeded. My point is: the most savvy companies contract annual sitewide pentests, in addition to all the other stuff they do to secure their networks, and virtually all of those pentests "succeed" (from the perspective of the testers). Further: not only have I never personally been on an internal network pentest (the kind where you start with an IP "behind the firewall" and nothing else) that failed, but I'm not sure I've even ever heard of one that failed. I'm certain there are some networks that are so resilient that they've stymied a competent internal pentest --- but again, I wouldn't know which one, because I've never heard of that happening.
- briandear 9y agoApple’s payments systems haven’t been breached, nor do I recall a breach of Stripe and I would bet my teeth that their security is far better and more proactive than Equifax — a company that’s entire business is based on data brokering. If they can’t handle the “cost” of correct security or, at the very least keeping dependencies updated, then they ought not be in business. If security makes it expensive, then perhaps there should be more competition? The credit bureaus have a near monopoly so they don’t have to be aggressive about security as a Stripe might need to be. That complacency and just general malfeasance means they ought to be sued out of existence. I bet any number of Silicon Valley startups have better security than Equifax — at far lower budgets. It isn’t a cost issue — it’s a competency one.
- tptacek 9y agoMore of my former colleagues work on the Stripe security team than at any other firm (besides NCC, our acquirer). They do a great job. But Stripe is a tiny company with very few products and a unified development culture with a management team organized around bringing technology products to market. And they aren't perfect. They will eventually screw something up. Comparing Stripe to Equifax is unreasonable. Equifax has about 10,000 employees. Stripe has less than 1,000. And, once again, please don't try to win an argument by putting me in the position of defending Equifax. That's not what I'm doing. My point is that practically every company of Equifax's size has similar problems.
- briandear 9y agoIf Equifax is too big to have their shit together, they ought not be allowed to store sensitive data. If this were a HIPAA situation, they’d be facing a statutory penalty of about $10,000 per record. Apple, Facebook and Google have far more data under their control than Equifax and they seem to take security far more seriously than Equifax. The Apple InfoSec team is extremely aggressive — InfoSec is ingrained in Apple culture. I am skeptical that Equifax takes security as seriously. Being “big” or “other large companies have the same problem” isn’t an excuse. They have no problem fucking people’s credit by reporting inaccurate information — they should be held accountable since that information has such severe consequences. My hatred of Equifax runs deep because they reported 7 state tax liens on my credit report that weren’t mine and were from a state in which I never lived. Despite providing all kinds of documentation, I ultimately had to sue them. I won the case and a bit of money, but the point is, they were willing to have a team of lawyers go to court against me and tie it up in court for several years — to defend something they knew was wrong. I even had letters from the state tax agency attesting to the error and they still had to be sued to fix the information. If their IT security is as arrogant as the rest of the company, then this breach doesn’t surprise me. How is that relevant? It’s highly relevant because they have demonstrated a willful disregard for facts. They demonstrate an arrogance based on their near-monopoly power over people’s lives. They don’t care about accuracy — they care about the appearance of accuracy. It follows that they aren’t good stewards of the information with which they have been trusted. The fact that they are too big and IT security is “hard” — that’s an excuse. General Motors might have bad IT security (I don’t know,) but they also don’t control the financial lives of almost every American. If they are so big that they can’t handle it, then they ought to be shut down. To be clear, I don’t have a problem with credit reporting. I have a problem with the fact that Equifax is going to survive this. Some big judgement happens, they’ll file for bankruptcy, they’ll reorganize and be right back at it.
- CJefferson 9y agoWe've dealt with this for hundreds of years. Your car kills people? Your biscuits are mouldy, or full of lead? We have strict rules, and companies that don't follow then end up in serious trouble.