4 ms·
It's this kind of morally righteous fury that bugs me. You compare web security to unsafe carnival rides? Please. Equifax had one of the worst breaches imagi
by eric_b 8y ago
It's this kind of morally righteous fury that bugs me. You compare web security to unsafe carnival rides? Please.
Equifax had one of the worst breaches imaginable. So did Target. Far as I know, no one died. You know, I don't think anyone even got injured. Did some people have to call their bank and dispute charges? Maybe.
Not really a life or death situation was it? I don't think Tesco or Betfair are really life or death either? Sure they should have better security, but is it worth becoming an angry mob about it?
- joepie91_ 8y agoYes, people do actually die from compromises, you just don't hear about it. For you, somebody snatching your CC might mean a hassle due to having to call the bank and dispute the charges. For somebody with little money to spend, it can mean the difference between feeding their family for 3 days and not doing so. For you, somebody leaking your private messages on a social network might mean some inconvenient messages that have to be explained to a friend. For somebody else, it can mean that suddenly their homosexuality is well-known in a country where that carries the death penalty, and gets them executed. Software is infrastructure, plain and simple. You don't maintain it, people die. You don't make it safe, people die. It doesn't matter whether you personally see it causing problems for yourself. This "morally righteous fury", as you put it, is absolutely justified. Developers (and the companies managing them) need to take some goddamn responsibility for the infrastructure they build.
- dsfyu404ed 8y ago>Software is infrastructure, plain and simple. You don't maintain it, people die. You don't make it safe, people die. It doesn't matter whether you personally see it causing problems for yourself. This "morally righteous fury", as you put it, is absolutely justified. Not all software infrastructure is critical infrastructure. It's like the difference between a company that makes bottom dollar kitchen sink sprayers and washing machine hoses that always leaking and mine railings making a town's water supply undrinkable. Both are water problems. Only one is a big enough problem that people not affected by the problem should care about the problem. You have to take both likelihood of harm and severity of harm into account. Just because someone somewhere might get hurt using a bottom dollar washing machine hose to transfer dangerous chemicals doesn't mean we should regulate all things related to water the way we regulate waste disposal near rivers and wetlands.
- joepie91_ 8y ago> Not all software infrastructure is critical infrastructure. This might be a valid argument if we had a standardized way of classifying critical software vs. non-critical software, that took into account corner cases. We do not. Instead what happens is that people arbitrarily classify what they consider 'critical' based on gut feelings and rarely considering the situation of people-who-aren't-them, and that the resulting potpourri of judgments produces critical systems where the authors of individual parts thought that it wouldn't be as critical as it ends up being. Then it breaks, and now all hell breaks loose. In practice, people build critical software systems with off-the-shelf components that really weren't designed to be used for such critical cases. This isn't specific to open-source, either; it happens just as much with proprietary components. There are no certification processes worth a damn, no clear idea of where and why this matters. And until we get to a point where those processes and standards do exist, there is only one safe assumption to make: all software is critical infrastructure, because you have no idea what it's going to be used for in practice. Hence the 'fury' being justified. EDIT: Addendum... I've had the critical-systems discussion with many developers. The overwhelming interpretation of "critical" is "I can see a way in which the software can directly kill people". Think drones, airplanes, and so on. Conversely, almost nobody considers the indirect consequences that might lead to that same outcome (no access to money, no access to healthcare, murderous stalkers, etc.). Let alone serious consequences that don't result in death. Realistically, barely anybody in the software industry has the first clue as to what constitutes a 'critical' system, or exactly how much damage their software can do. A similar issue exists in the design industry[1]. [1] https://www.youtube.com/watch?v=J0ucEt-La9w https://www.youtube.com/watch?v=J0ucEt-La9w
- dsfyu404ed 8y ago>Addendum... I've had the critical-systems discussion with many developers. The overwhelming interpretation of "critical" is "I can see a way in which the software can directly kill people". Think drones, airplanes, and so on. >Conversely, almost nobody considers the indirect consequences that might lead to that same outcome (no access to money, no access to healthcare, murderous stalkers, etc.). Let alone serious consequences that don't result in death. That's how things work in every other industry that doesn't specifically build things to operate in hazardous environments. Things are designed to not kill and/or harm in normal use, not to not kill and/or harm people in exceptional circumstances or if grossly misused.
- BlahBoy3 8y agoJust because it's not a "life or death" situation doesn't mean people shouldn't say something. What kind of attitude is that? I mean, is the rule for when we should speak up against negligent practices or stay silent really "if no one will die, it doesn't matter"? There are other types of harm people can suffer other than just physical harm. And those other types of harm are no less significant or noteworthy, at least in my opinion.
- Fradow 8y agoThink again, having to deal with identity theft have seriously derailed some people's life. I wouldn't be surprise if there was a few suicides that could be directly tied to a specific breach. There might be a line to be drawn, for example I don't expect a small shop to adhere to all the last security recommandations. But a big company handling highly sensitive information at scale? It should be a crime to have a leak caused by a well-known issue. Unfortunately, there was barely any consequence, as far as I know. Those companies certainly have the means to keep up with security requirements, and it should be mandatory considering their business. Until they act properly, shaming it is.
- vorpalhex 8y agoMy mother spent two months without a functional credit or debit card because her identity was stolen and it took a marathon of paperwork and disputes. Thank goodness she has family who was able to give her a sizeable amount of cash during that period. I suspect many are not so lucky. What about people fleeing abusive spouses or other folks who have a very real reason to keep things like their address under wraps? There was a training school that recently leaked the addresses of it's participants - several of whom were undercover police officers. Don't get me started on the OPM breach. Just because a breach doesn't affect you very much doesn't mean there aren't serious consequences. When every single business has horrendous amounts of information on me, any minor breach becomes a major problem.
- BeetleB 8y ago>My mother spent two months without a functional credit or debit card because her identity was stolen and it took a marathon of paperwork and disputes. She was lucky. I know someone for whom the process took over a year. Because of that he had to wait before he could buy a house - his mortgage wouldn't be approved until all the mess was cleared up.
- athenot 8y agoWhat's infuriating is the claim from those companies to be secure when they aren't. If, as you suggest, they should be given a pass on data safety, then they should be barred from making promotional statements about data safety. They violate the social contract by making false or misleading claims.
- BeetleB 8y ago>Not really a life or death situation was it? It very much can be. Look at some of the largest cases of embezzlement/fraud in history where many people's life savings/retirement were completely lost. In the short term, some people commit suicide. In the longer run, they die of poor health because they don't have much money when they're old and sick. Although I don't know anyone who committed suicide, I do personally know people impacted by what at the time was the largest case of embezzlement in history (back in the 90's). I've seen the impact it has. And I can assure you, shaming a public company is nothing compared to what those people go through. If we had a better hammer to coax the companies to fix these things, I would advocate for it. For now, public shaming is not effective enough an approach.
- colemickens 8y agoBeyond the identity theft example, Ashley Madison wasn't that long ago, and explicitly without passing judgement, I'm pretty sure that was highly disruptive to a number of peoples' lives.