4 ms·
I hope more public security shaming like this happens, consequences and lawsuits be damned. This is getting too tiresome, we've been tolerating incompetence and
by outoftacos 9y ago
I hope more public security shaming like this happens, consequences and lawsuits be damned. This is getting too tiresome, we've been tolerating incompetence and bad management for too long.
- FLUX-YOU 9y ago>I hope more public security shaming like this happens This has been going on for a few years at least from my perspective. Shaming doesn't work well enough IMO, but maybe that's because I haven't seen or heard from companies who got shamed and then changed. Anthem and Target hacks were both high in the news, but both settled all of their lawsuits.
- AnimalMuppet 9y agoYes, this is incompetence. Gross, egregious, horrible incompetence. Problem is, though, it only takes one incompetent person - or even one person making a mistake one time - to open the door for a massive breach. Requiring perfection of humans in order to maintain security... that's not a workable approach. Yes, this was inexcusable. But also, our current approach to security is fatally flawed.
- tambienben 9y agoSo what approach do you recommend?
- Kluny 9y agoCriminal charges against the company for security negligence. Seize their assets and close them down. Back in the 90's hackers used to get criminal charges for getting into secure systems. Now tech companies are a little more intelligent about it and they pay bounties to hackers. It should go all the way in the other direction though, the responsibility for getting hacked should fall on the company that gets hacked for their shit security.
- FooHentai 9y ago>Problem is, though, it only takes one incompetent person - or even one person making a mistake one time - to open the door for a massive breach. In the absence of effective governance and process, sure. But half the point of them is to ensure the single-actor miscarriages get caught and handled. The real problem today is that the maturity of an organization's governance/process is not directly linked to the sensitivity of the data being protected. Instead it's linked to the size and age of the corporation, and the amount of resources (people, money) available to expend on them. For systems of this kind of scale, for organizations of this kind of size, handling data of this level of sensitivity, you'd expect a huge bank of governance and process designed specifically to guard against single-actor breaches. Things like active automated monitoring for change to the network and systems, full change control/approvals process, system certification, risk analysis, penetration testing. These things are hard to implement, take time, and are a significant investment that lacks easily measurable benefits. It doesn't help that this stuff is seen as 'not sexy', either.