5 ms·
> I'd also note that these companies are barely (if ever) held liable for life-compromising hacks on their platforms. You do know it is impossible to stop all
by PatientTrader 9y ago
> I'd also note that these companies are barely (if ever) held liable for life-compromising hacks on their platforms.
You do know it is impossible to stop all cyber attacks? Its always a matter of when, not if. Zero day attacks are developed everyday with not even the best funded cyber security systems able to thwart them. The geniuses are on the offensive side, if they want in, they will get in.
- FilterSweep 9y agoYou didn't really address the point you quoted. The problem isn't that someone is getting IN; it's that the company throws up their hands and says "tough sht." Or in a worse case, when Equifax puts up a compromised site to find if you were hacked that requires a significant amount of your SSN and personal details. (edit: format)
- PatientTrader 9y ago> it's that the company throws up their hands and says "tough sht." What exactly is your solution to the problem? You are more or less complaining without providing any insights into addressing the issue or without knowledge of the threat landscape.
- toomuchtodo 9y agoSpending money on security architecture/engineering/pen testing/etc in concert with government regulation/oversight. Full disclosure: I work in security architecture/risk management in the financial services industry.
- throwaway2016a 9y agoWhile I agree, as a CTO I would be terrified if a data breach could hold me personally liable. It'd be like a Director of Security at a bank being liable for their bank being robbed with a tank. But at the same time there is a line. I would be for holding companies liable if, for instance, the data gets out there and you find it is entirely unencrypted and the passwords are MD5 hashed or plain text. There has to be a baseline. Mistakes should not be punished as long as there is not also negligence.
- ryandrake 9y agoThe Director of Security at a bank should at least be fired if their bank is robbed by a guy brandishing a banana. I'd speculate that that's the nature of most data breaches: amateur attackers taking advantage of grossly incompetent security.
- darepublic 9y agoWell I think bank tellers where I live are instructed to comply with robber's demands for money even if they are not visibly brandishing any weapon
- daveFNbuck 9y agoNo one said anything about holding the CTO personally liable. The idea is to hold the company liable. This makes sense because the company is in the best position to prevent the bad outcome. If the company is always liable, it can find an optimal balance between the costs of security and the costs of breaches. If the company is only liable when negligent, it is incentivized to minimize the cost of security to the bare non-negligent minimum. This pushes all the costs onto the people whose data are compromised. These people are not in a position to spend small amounts of money to dramatically lower the expected costs of breaches, so they just end up paying huge costs that cannot be mitigated.
- nathan_long 9y ago> While I agree, as a CTO I would be terrified if a data breach could hold me personally liable. Personal liability is going too far, IMO. > Mistakes should not be punished as long as there is not also negligence. The problem with this is that you'd have to enshrine, in law, what "negligence" is. Technology changes too fast to put that into law. "How many people got hurt and how badly?" is a question attorneys can reasonably address. "Was there sufficient input sanitization?" is not.
- mnw21cam 9y agoFrom my random perusal of the various reports of compromises over the last few years, my impression is not that organisations tend to get hacked using the latest zero-day vulnerability, but rather that organisations get hacked because they have glaring security holes that you could drive a double-decker bus through. For example, bcrypt has been around for how long now? And don't almost all the reports of hacks report that a database was lifted with usernames and passwords either in plaintext (for the love of all that is holy) or hashed with unsalted SHA1, or similar?
- jrimbault 9y agoI think most "hacks" have been the results of social engineering and misconfigurations rather than software/hardware vulnerabilities.
- talmand 9y agoI keep plaintext passwords, but I reverse the string to prevent the hackers.
- gkya 9y agoI wish there was a "web security checklist" where if you ticked all the boxes, you can be pretty sure you have the well-known holes covered. This is why web frameworks are really useful, the decent ones get you way ahead in securing your application from the most common attacks. But if you self-bake, then you have to manage the entire complexity of the web platform.
- nicoburns 9y agoThis doesn't cover everything, but it's a pretty good starting point: https://stackoverflow.com/questions/549/the-definitive-guide-to-form-based-website-authentication https://stackoverflow.com/questions/549/the-definitive-guide...
- deejaybog 9y agoOWASP top 10 is as close as it gets to a checklist: https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Proje...
- gr3yh47 9y agoIt's not impossible to stop most though. and Hacks like sony, equifax, linkedin and many others are the result of what should be criminal negligence. I.e. not encrypting sensitive personally-identifiable information. instead of investing in securing their customer data these companies pad their bottom line. so yes, they should be held accountable for failing to follow basic industry-standard data protection practices.
- gkya 9y agoThe industry is held to no standards at all. You can keep plain-text passwords in your databases, do no tests at all, and be incompetent in a million other ways. I usually get downvotes when I say this, but by now there needs to exist certain regulation on commercial software and software-based services. It should be ensured that certain practices are followed in security and ethics (do you take the basic, well known precautions against the well-known attacks?, do you respect your users' privacy at least as much as the law requires you to, do you follow the terms and conditions you declare?). What we need is CE for software, and it's sad that I can ensure my cheese comes from a certain town and is produced from the milk from cows eating according to a certain diet, but not if Twitter (or any other commercial website) hashes and salts my password, and actually uses basic precautions against CSRF or what not. These companies should be obliged to get their stuff audited by third parties, and there should be a way to tell if they are really approved to maintain a certain standard in producing their software. I do understand and share the hacker culture, and appreciate how it's possible to spin off a start-up website business on the internet, but business is business. You don't become exempt from regulations when all you do is to run a tiny B&B with 2 rooms. Similarly, as soon as you're a company selling online services, regulations and standards should kick in. Because by now those online services are no less important than food business. You say it's impossible to stop all cyber attacks. Then, as it is impossible to stop all burglary attempts, should banks just deposit their money in some apartments, or in some random rooms where all the security is a wooden door? Fire all the security guards because it's impossible they survive all the guns out there? These companies like LinkedIn are no different in banks insomuch as they deposit not our money, but our personas. They should actually be more cautious because while money can be replaced, nobody can have a new self.
- xoa 9y ago>You do know it is impossible to stop all cyber attacks? This is a fallacious argument, specifically the Nirvana Fallacy. Perfection not being achievable in no way means that there can't be standard best practices that are a minimum requirement, nor that liability cannot still exist. Certain types of cyberattacks are in fact possible to stop perfectly merely by virtue of not holding onto information at all. As a trivial example, there should be no plaintext password leaks (or even easily brute force password leaks) at all, ever. Adaptive hashes/key stretching have been a thing since the dawn of security, Robert Morris described CRYPT for unix password usage in 1978. bcrypt is from 1999. There has been no reasonable basis at all for plain text or even raw fast hash primitives to be utilized, ever, yet they have been. In no other industry dealing with these kinds of privacy and safety concerns is that sort of practice considered acceptable, not should it be. Holding personal private information at all long term should fundamentally be considered a liability situation, because it's not necessary, it's a commercial choice. Can't be hacked if it doesn't exist. If businesses choose to hold it, they should also be taking reasonable steps to protect it, and accept liability for failures. That's the natural balancing flip side to them getting profit from using it. If they're allowed to turn any costs of holding it into externalities that distorts the market.
- TallGuyShort 9y agoYou also can't stop all failures of infrastructure, but outside of computing, anyone calling themselves an engineer is generally required to hold to various ethical and professional standards or have their work signed off by someone who is.
- da_chicken 9y agoIt's impossible to build a house that can't be burglarized. Does that mean you shouldn't lock your door when you leave in the morning?
- talmand 9y agoSilly; it's impossible to stop all murders, therefore we shouldn't bother with making it a legal liability. If the criteria is that it must be possible to stop all instances of an action to make it a legal issue, then we should just shut down all the prisons.