9 ms·
You prefer blaming the victim instead of the perpetrator of the crime?
by assblaster 8y ago
You prefer blaming the victim instead of the perpetrator of the crime?
- ecnahc515 8y agoI mean, the blame is somewhat shared. Blaming the perpetrator only helps so much. It's reactionary. It's similar to the reason you get insurance before bad things happen, not after. You can blame perpetrators all you want, but you still need to protect yourself.
- sgolestane 8y agoSo it's my fault if someone steals a package from my porch?
- flukus 8y agoNo, but if you borrow my stuff and it gets stolen off your porch then you're also to blame because you didn't protect it responsibly.
- deleted 8y ago[deleted]
- AnimalMuppet 8y agoMorally? No. It's the thief's fault, and the thief's fault only. But if you know that people steal packages off of porches in your neighborhood, and you leave a package out there for weeks, you're at least being pretty unwise. You're not morally at fault, but pragmatically, yes, you kind of are. [Edit: That is, your actions are not well-suited for the kind of world that we actually live in, and that you know that we live in.]
- timClicks 8y agoNot your fault in a moral sense, but it certainly is in a causal sense. You could have set up a different causal chain that would have prevented the theft. Of course that doesn't mean that society can't blame (and punish) the thief.
- Varcht 8y agoIf a package is taken from a porch and there is no Ring camera to record it did it make a noise?
- threeseed 8y agoWhat we are actually talking about is you putting your valuables in a safe within your alarmed house and a professional thief breaking in and stealing it. Because the thief previously worked at the safe company and implemented a backdoor in the design. You want to explain how you defend against that ?
- nickpsecurity 8y agoWhat we're actually talking about, if we consider security evaluations and ratings, is to... 1. Put valuables in a low-rated safe whose door opener is network accessible and itself low-rated. 2. Whose alarms suck at identifying and responding to actual breaches by even the most common methods. 3. A thief breaking in who uses the most common methods that the safemaker or company didn't try to stop. They did spend a fortune on unrelated stuff. 4. Various designs and implementations that weren't using methods that often prevent or detect backdoor attempts in favor of methods that let backdoors slip through. Also, this is a company that makes billions in profits a year. They have the money to both develop and build highly-secure systems, including safes. They keep not doing that or not using what high-security they build. They keep using low-security stuff year after year after year. They could defend against those problems by doing more of what works and not using low-rated, often-vulnerable stuff for protecting secrets. Just a hunch on my part. ;)
- dx87 8y agoWe don't know how the companies were compromised, so we have no way of knowing if they were capable of protecting themselves. A state sponsored attacker has effectively unlimited resources, so at the end of the day, the company would go bankrupt trying to protect themselves against every concievable attack. It's one thing if they were negligent, but just saying that they should have protected themselves better is like blaming an Iraqi company for not protecting itself from being blown up by the USA. Some threats are just too large for you to protect against.
- ep103 8y agoCompanies aren't liable for how stolen information is used, so they don't invest in security. Want to prevent this from happening? Make companies liable for how stolen information is used, and overnight watch as security becomes a first thought at most companies, instead of ignored entirely.
- assblaster 8y agoCar thief steals your car from your garage. Car thief crashes car into crowd of people. Crowd of people sue you for damages because you didn't make your garage secure enough? Why didn't you hire a 24/7 security service to protect your property to decrease risk?
- toufiqbarhamov 8y agoWhat you’re facetiously describing actually is a thing in legal settings, just not with your locked car. If you left your car in front of an elementary school all day, keys in the ignition and running, and some preteen joyrides it into someone, brace yourself. In the same way that if kids climb your inadequate fence and drown in your pool, you’re screwed. I think it’s more than fair to say that reams of personal info stored by companies is such an attractive nuisance.
- jstarfish 8y agoSee what happens when a kid drowns in your unsecured backyard pool on more than one occasion or brings your unsecured handgun to school more than once. I get that it's liberating to disclaim responsibility for the consequences of anything we do, but that isn't how the world works. At some point (however far) you are held responsible for your negligence.
- excalibur 8y agoIf you are running a for-profit parking garage? Absolutely.
- tucaz 8y agoif I was a parking garage that made money by keeping my clients car and 1) other similar companies did the same and had their cars stolen over and over again (so I know it is likely or at least possible) and 2) thieves killed hundreds of people by using the stolen cars and 3) I didn’t provide any sort of damage reparation to my clients then: yes. Or, how about they explicitly tell their customers that they can’t keep their data safe and might be a target of an attack that harms the customer? I’m ok with either option. There is an implicit expectation/contract that if a company is collecting your data it will keep it safe. If it’s not going to do that and will not do anything afterwards to repair any damages caused then they should just delete it after using that data or, advertise they can’t keep it safe and let the customer decide.
- pestaa 8y agoDon't let these huge corporations overplay the victim card though, withholding information from customers how their systems might be affected is also unacceptable.
- toufiqbarhamov 8y agoThe whole concept of a victim probably isn’t appropriate when referencing a large corporation. Even if it is, what these companies did after being victimized is certainly something deserving of a portion of fault, along with the hackers.
- dnbgfher 8y agoThis is an absurd appeal to the whole victim-blaming awareness trend. That's about an individual going about their life and having a crime perpetrated on them, which primarily negatively affects them. This meanwhile is about a corporation entrusted with valuable information/access with the understanding the corporation would take appropriate measures to secure it. The victims here had an obligation to those they worked with to take reasonable measures to prevent and mitigate this sort of thing. Just because something bad happened to them doesn't relieve them of this obligation. It's possible for more than one party involved to be in the wrong. Just because the victims screwed up doesn't mean the perpetrator is somehow morally cleared. Nor does the perpetrator clear the victims of their carelessness. Edit: Since apparently people are taking this to mean I think companies should withstand a dedicated attack by China, I've gone wrong somewhere. I don't mean that. I was talking about responsibility. They can both be responsible and not be negligent. What I expect is them to help clean up afterwards. Just because they failed in an understandable way doesn't mean they get to avoid taking actions to ensure the damage is minimized.
- dx87 8y agoWhat should the companies have done to protect themselves against the state sponsored attack? The article doesn't say how they were compromised, so what "reasonable measures" didn't they take to mitigate being targeted by a powerful nation?
- excalibur 8y agoThis is a fair point. Many of these large data breaches are revealed to be the result of negligence on the company's part (and often the company faces few to no consequences beyond public shaming). But in this particular case we simply don't have enough information yet to make that type of claim.
- dnbgfher 8y agoSure, maybe this was something beyond what could be reasonably prevented by a non-state. I don't think we know yet. But they have a duty after the fact as well, to ensure the damage is minimized. That includes actually telling those potentially impacted what is known, etc.
- logicallee 8y ago>You prefer blaming the victim Victim? More like "reckless dilettante". If you're not perfect in this world what are you even doing in society, I mean anyone who cares about security wouldn't program in a programming language that begins with a letter or a number, because perfect code in those languages is impossible. And setting up a server or using a cloud host? Ha! Every single one of those is vulnerable. It's like walking around. If someone goes to the store and isn't wearing an iron man suit of armor of course it's their fault for not being perfectly protected. You can hardly blame someone for dismembering them on the spot and stealing a kidney, I mean it's right there. Just wear a suit of armor and have a security detail accompany you, and if you can't then what are you doing buying eggs? Stay home if you are not willing to do what it takes to participate safely in society. And it goes without saying, subscribe to suit of armor advisory lists and if there's a new kind of knife, apply patches all over your suit. At a minimum. Or just stay home. I would never do anything that involves a computer. Basic responsibility.
- gpm 8y agoThey aren't the victim. The victim is the people they helped hack, and the people whose private information they helped leak. This is like defending a teacher who left a loaded gun on their desk because they are the victim of theft.
- ineedasername 8y agoWe don't have details of the attack so we don't know if the gun was left on the desk or if, to extend the metaphor, the gun was left in a safe the criminal helped design with flaws it could exploit. Or just a safe it knew how to crack. Now, what the company did afterwards in notifying ( or not) customers and others affected, that is on the company.