5 ms·
I think it's all relative really. I don't really worry about these sorts of exploits because I'm not a high value target whose going to be attacked by most scar
by chundicus 7y ago
I think it's all relative really. I don't really worry about these sorts of exploits because I'm not a high value target whose going to be attacked by most scary exploits. Certainly there are exceptions, especially when the exploit casts a wide net and doesn't care about who it hits. Your trust in your HW and SW should be proportional to the risk. I would hate to have my private data leaked, but realistically it wouldn't be much more than a nuisance I have to sort out. The same is not true for a government agent or a CEO for example. It would be nice if we could just 100% trust all our software and hardware, but it's just not practical these days.
- tasty_freeze 7y agoYou are a worthwhile target at a minimum that your machines can be used as part of botnets and DOS networks. Sure, they might not be digging out your bank account number, but since the cost to the attacker of compromising your machine might be nothing more than a few hundred packets, they'll try anyway.
- deleted 7y ago[deleted]
- chundicus 7y agoSure, which is why I mentioned the "wide net". I take reasonable precautions, apply basic monitoring, and take care with what software I'm downloading so that I lower my risk of this. It's not foolproof but it's good enough to keep me from being an easy target, while not sacrificing any convenience or spending a lot of time fortifying my machine.
- SlowRobotAhead 7y agoEvery small time accountant, car dealer, mom and pop shop, and school thinks “there are bigger targets than me!”... then they’re dealing with ransomware. It’s just another form of “I don’t break the law! I have nothing to hide”.
- chundicus 7y agoRegularly backup and keep those backups off your network, boom problem solved. My point was not that I take no precautions or that you're not at risk because you're not a government agent.
- SlowRobotAhead 7y agoOk, aside from the time it takes to restore from backup... What about ransomware + spyware where you just lost account numbers and IP? Just stop. There is zero reason to be reckless with infosec and IT infrastructure. Sometimes things will exist outside of your control but that’s a long shot away from “whatever, it won’t happen to me”.
- chundicus 7y agotime to restore from backup really is not a personal concern "whatever it won't happen to me" isn't my point, but okay. I'm not advocating for recklessness or apathy toward infosec / IT. I'm not trying to tell anyone how to live their lives, and explicitly I'm not saying what a company should do. I'm just trying to convey how I view MY risk from a target probability perspective vs the loss it would incur, and thus how I decide to trust some HW/SW Not sure why you're trying to strawman me here, no need to be hostile