3 ms·
> The first is, have we decided that the ends always justify the means? It seems in other domains public shaming is unacceptable. Troy himself despises Donald T
by noxToken 8y ago
> The first is, have we decided that the ends always justify the means? It seems in other domains public shaming is unacceptable. Troy himself despises Donald Trump, but one of the things most heinous about 45 is his use of Twitter to publicly ridicule and shame companies and individuals. And now Troy is engaging in exactly the same behavior. But it's "OK" this time? What is different?
Intent has a lot to do with it, but to me, I see one as part of business. As another comment said, some of these companies carry enough information to ruin our lives. It makes sense to hold their feet to the fire in a public forum when they put security on the back burner.
>The second thing that troubles me is security "best practices" today may not be best practices tomorrow. Some of his example companies are using practices that were "best" 10 years ago. What happens in another 10 years when Troy's current advice is outdated? More pitchforks?
Security is notoriously hard, and anyone who has ever tried to get into the space understand that. But just because it's hard doesn't mean that you get a pass. It is the duty of the business in question to protect customer data. I believe that it is reasonable to expect a company that has my account and personal information to do everything that it can to protect that data.
You said elsewhere that if a breach occurs, a customer only has to dispute a few charges with their bank. You're right. It is much easier for a customer to dispute fraudulent charges. But why do I need to spend my time filling out forms and cooperating with a minor investigation because a business (through negligence or otherwise) lost something that I trusted them with?