3 ms·
Like many things in life, the fight between good actors and bad actors online is a state of dynamic equilibrium. Everybody loses money to fraud, but as long as
by yding 7y ago
Like many things in life, the fight between good actors and bad actors online is a state of dynamic equilibrium.
Everybody loses money to fraud, but as long as they invest enough money and resources they can keep those fraud losses to an acceptable level. Because criminals are infinitely creative, the problem will never be "solved." There will always be new moves and new countermoves.
Total security is an illusion. Everyone who's worth hacking or worth defrauding will get hacked or defrauded sooner or later. The people who have made the necessary investments are able the contain the damage. The other ones, or the really unlucky ones, end up dying off.
- munk-a 7y agoTotal security is possible but unrealistic. In our modern world we have terrible baseline security, we can do better with some trivial adjustments that the market is countering with a strong disincentive because we as a society haven't placed a clear value on security (outside EU where GDPR has flaws but is an attempt to reward good actors). This is essentially equivalent to a tragedy of the commons mixed in with a race to the bottom - companies are currently penalized for practicing good security, they are voluntarily accepting lower profit margins in exchange for something nobody cares about, they're also losing access to some supplemental revenue through reselling customer data. If we add decent incentives and make it economical to follow a "good" path we can increase our baseline of security, hacks will always happen but we can minimize the costs of those hacks and their frequency with best practices. Heck - my standard line with companies w.r.t. PII is that "Your proposal is essentially to collect everyone's alarm code into your safe, your safe has gone from something nobody is interested in to something that, if compromised, could lead to a bunch of people being burglarized." the issue is that over-collecting PII and then, shucks, losing it in that completely unavoidable security compromise, doesn't lead to appreciable punishment for the company - in the real world it sure does (if your locksmith copies your key an extra time then gets burglarized and the burglar uses that extra key to burgle your house the locksmith is absolutely liable and may be found to be a conspirator). It's anomalous that these two worlds are in contrast. All that said, I absolutely agree that it's a balance and there aren't super simple answers here, but it's important to reject the thought that being as vulnerable as most businesses are is acceptable.