7 ms·
Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in
by kardashev 9y ago
Aaron Swartz faced 35 years in prison for leaking JSTOR articles.
Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens.
You better believe they'll care about security then.
Many companies would also rethink whether they need to track and keep personal information at all.
- 1690v 9y agoThat is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.
- toomuchtodo 9y agoWhy is a software developer an engineer when it fluffs their ego, but not an engineer when regulation and consequences for failures are necessary? Yes, if the security failure is grossly negligent, you should face criminal proceedings. As a C level executive, you are responsible for your chain of command.
- zpr 9y agoBy that extension if a McDonald's drive thru employee accidentally spills hot coffee on a customer, the CEO is responsible and should be charged with assault?
- toomuchtodo 9y agoIs that grossly negligent? No. Is keeping the coffee excessively hot for cost reasons, thereby causing the customer to receive third degree burns on their genitals and winning in court? Yes. https://en.m.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Restaurants https://en.m.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Rest... Your culture is set by your leadership. Make good choices.
- zpr 9y agoI'm familiar with the case, that's why I mentioned it. My point was that although they lost the civil suit, there weren't any criminal proceedings against C-levels. I understand the argument of negligence being as guilty as malicious intent but it creates a sweeping blanket that's hardly fair or enforceable. I agree with your principles in theory but it's just impractical.
- toomuchtodo 9y agoThe Department of Justice was able to dismantle Arther Anderson after their fraudulent audits of Enron. Lots of things that are impractical are possible with sufficient effort. And the government has unlimited resources for those efforts. You must hold systemic negligence and corruption accountable, or it perpetuates the cycle.
- kasey_junk 9y agoA) The DOJ had been looking at Anderson for years prior to Enron due to irregularities with other major firms like Waste Management Inc. Enron was not an isolated incident. B) They were prosecuted for the very specific crime of obstruction of justice after they were caught destroying evidence. It wasn't some backlash against a nebulous problem. C) Their conviction was overturned! I'm not sure you could have picked a worse example for arguing your point.
- deleted 9y ago[deleted]
- ams6110 9y agoThey keep the coffee that hot because customers like hot coffee. That's the main reason I get coffee at McDonalds, not because it's great coffee (though it's not bad) but because it's HOT. Half the time I get coffee at Starbuck's it's only a litte better than piss-warm.
- 9y ago
- deleted 9y ago[deleted]
- wybiral 9y agoIf they create a work situation where by cutting corners on container safety, protocols, and employee attentiveness I think they are guilty. And in the modern security context we're pushing deadlines just to race to the latest features with almost no regard for security in the process. Something has to change. If this kind of negligence were causing similar problems in physical realms there would be regulations. The tech companies behind these mistakes won't have that free roam forever. Every major screw-up is a step closer to regulations and everyone will cry about it when it happens... But so many companies today don't seem like they're ready to behave responsibly.
- kasey_junk 9y agoIs there any evidence that software engineers are protected in some way from criminal negligence cases? The reality is that it is vanishingly rare for any engineer to face criminal charges for their professional actions. It doesn’t seem to me that software is held to much lower a standard.
- toomuchtodo 9y agoNot protected, simply not pursued, although it’s usually outright fraud that is the target of most prosecutions. Watching the SEC closely to see how many ICOs they prosecute. Also was helpful to see someone involved with their breech response who attempted to profit from non public material information prosecuted (although that’s tangential to the breach itself). Someone relatively important is going to have to get burned before more software professionals are pursued for grossly negligent security failings.
- kasey_junk 9y agoYou misunderstand my point. Are there examples of other sorts of engineers being brought up on charges? It only happens in the most egregious of negligence cases as it is and even then convictions are rare. I'm saying your impression that software engineering is protected is wrong, because no engineers (to any normal approximate) are brought up on criminal charges.
- cbcoutinho 9y agoLawsuits are commonplace in civil/geotechnical engineering because faulty work has life and death consequences for the general public. To be a certified professional engineer and sign-off on design plans in California you need to pass an exam, after which could result in issues of liability. This law practice defends professionals that may be in a dispute [0]. Here's a breakdown of why engineers might get sued [1]. Here's a case where a company was held liable for damages associated with a construction project [2]. The title 'software engineer' without any notion of liability is an exercise in stroking ones ego. [0] https://mylicenseattorney.com/california-board-for-professional-engineers-and-land-surveyors/ https://mylicenseattorney.com/california-board-for-professio... [1] https://design.insureon.com/news/3-reasons-engineers-get-sued https://design.insureon.com/news/3-reasons-engineers-get-sue... [2] http://caselaw.findlaw.com/ca-supreme-court/1671856.html http://caselaw.findlaw.com/ca-supreme-court/1671856.html
- thrownaway954 9y agoit's unfortunate but leaks and breaches happen in programs (which a website is). it's coding, it isn't perfection and no one should go to jail or be ridiculed because they unintentionally introduced a bug that caused whatever problem arise (WE HAVE ALL DONE IT). This is why it is ideally best to have some sort of peer review and/or buddies reviewing our code for things we don't see before they are pushed into production, however unfortunately, this doesn't happen in all cases. the only crime was not fixing the problem and keeping it a secret AFTER IT HAD BEEN DISCOVERED. in this case, it wasn't the mistake that was the crime, it was the cover up.
- richsherwood 9y agoEngineers in other disciplines are held liable for their mistakes. Imagine a civil engineer signing off on a building and then having it collapse. If it was found that the engineer was negligent then you can bet your ass there will be reprucussions. As an engineer, you are the top of your field and with that comes a professional responsibility that is important to fully realize. Mistakes are mistakes sure, but if those mistakes end up being responsible for criminal activity then you’re fully responsible. It’s why the chain of command exists.
- zimpenfish 9y ago> Engineers in other disciplines are held liable for their mistakes. To be fair, they have several hundred (if not thousands of) years of trial and error, documentation, etc. behind them to (try and) help people avoid the mistakes. Computer Science has barely 70 years of half-arsed fumbling about.
- arkades 9y ago> imagine a civil engineer But there isn’t an equally trained engineer dedicating his energy to taking down the bridge - it only has to not collapse under normal usage. When a bridge is intentionally destroyed by enemy action, it’s engineer is not held liable.
- toomanybeersies 9y agoItaly jailed scientists for failing to predict an earthquake, despite the fact that it's not possible to predict an earthquake. They were eventually acquitted, but the very fact that they were even charged in the first place is ridiculous.
- stef25 9y agoDidn't Iran put a developer in jail cause some of his open source code was used on a porn site?
- notyourday 9y agoSounds like an excellent idea: Jr. Developer - automatic pass. Low money Sr. Developer - likely a pass, provided 'i' are dotted and 't's are crossed - decent money Tech Lead - no pass unless tried very hard to get it resolved, big money Exec - no pass, very big money
- PakG1 9y agoI'd revise that from "if a breach happens" to "if a breach happens and the CSO demonstrated criminal negligence." The attack surface for security is too large, and it's not fair to hold a CSO of a cafe chain to such a standard when zero-days are also possible. Punish for being negligent, not for being attacked by a zero-day, or something else really obscure.
- Kerrick 9y agoWhat if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?
- bradleybuda 9y agoYes
- tptacek 9y agoWhat if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advisory role in the organization, and the real institutional power comes either from engineering or from the CIO. This security director handled Dylan's bug report badly and deserves the reputation hit he's getting. But if we're going to suggest liability (let alone criminal liability) for security flaws, we should at least have some idea of what it is we're regulating.
- smileysteve 9y agoPull the plug. The final "stick" and reason for a C in the title is the responsibility to shut down the data (and website) until such a point it can be secured. It's should be considered more of a fiduciary duty (protect shareholders, customers) to protect data as making the right investment or HR decisions.
- RKearney 9y agoAaron Swartz faced 35 years in prison for breaking and entering and unauthorized access of a computer network / hacking amongst other things. It's a shame it ended the way it did, but please don't downplay what he did and use his name to push an agenda.
- Buge 9y ago> breaking and entering Is that true? It was an unlocked closet. The walls were covered in graffiti.
- coldtea 9y ago>Is that true? It was an unlocked closet. The walls were covered in graffiti. So, if your house has the door ajar, and the walls are "covered in graffiti" it's open for all?
- Buge 9y agoIt wouldn't be breaking and entering. And a house is different than a school. MIT has an open campus. MIT has a long history of celebrating students who transgress boundaries and go where it is unexpected[1]. I don't have a history of celebrating people who enter my house uninvited. > Swartz had connections to [MIT]: "He was a regular visitor to the MIT campus and interacted with MIT people and groups both on campus and off. … He was a member of MIT's Free Culture Group, a regular visitor at MIT's Student Information Processing Board (SIPB), and an active participant in the annual MIT International Puzzle Mystery Hunt Competition. Aaron Swartz's father, Robert Swartz, was (and is) a consultant at the MIT Media Lab. Aaron frequently visited his father there, and his two younger brothers had been Media Lab interns." [2] If a good friend of mine sees my house has the door ajar, and the walls are "covered in graffiti" it would be perfectly reasonable for him to check inside. [1] https://en.wikipedia.org/wiki/Hacks_at_the_Massachusetts_Institute_of_Technology https://en.wikipedia.org/wiki/Hacks_at_the_Massachusetts_Ins... [2] http://swartz-report.mit.edu/faq.html http://swartz-report.mit.edu/faq.html
- 9y ago
- joering2 9y agoTrue but worth mentioning different forces were at stake there and here (although both very dark). In Swartz case, prosecutor was trying to make example of him because his public University made/is making tons of money for providing information that should be free (or already is) In this case, I would imagine they want peoples info to be leaked and exposed as much as possible, just to have a good reason to fine those for-profit private companies. Edit: in other words - show me a priest who doesn't want you to sin, or a cop who doesn't want you to break the law, or a doctor who is not fine with people getting sick. Otherwise they would all be out of job.