4 ms·
Looks like the developer in question took action to correct the situation the same day they became aware of it. That at least is good. If the data was never se
by sosuke 6y ago
Looks like the developer in question took action to correct the situation the same day they became aware of it. That at least is good.
If the data was never secured in the first place can you call it a breach?
They found this, great, was there any indication it was accessed directly before that? Is that something that can even be investigated?
You find a door to the data unlocked. You open the door. Can you tell if someone else had opened the door before you? Did you prevent 845 GB of data being found by a black hat or did you find that data because of a black hat?
- MaximumYComb 6y agoI doubt they have sufficient logging if they didn't have any security on their data.
- boomlinde 6y agoAs a user concerned with my own privacy, I don't care about the color of the hat. If it's for my eyes only and someone else looks at it, it's a breach of privacy. If that's due to the incompetence of someone I've entrusted my private information to, it's a breach of trust. If that's someone with a legal responsibility not to share the information, it reflects very poorly on them, and this level of negligence should in my opinion be considered criminal.
- ashtonkem 6y agoIt’s a good practice for good faith security researchers to create their own account so that they can test the system without viewing an innocent users data. This is especially important for systems such as dating apps, which obviously contain extremely sensitive data.
- thephyber 6y ago> If the data was never secured in the first place can you call it a breach? Yes. It's a "breach" even if just a security researcher found it. It's sometimes even a breach even if only an employee found it (depending on the specific role of the employee and controls on the data). > They found this, great, was there any indication it was accessed directly before that? Is that something that can even be investigated? You can be found "not guilty" by a jury, but that doesn't mean you are innocent. Sometimes there just isn't enough evidence of the crime. We should care more about whether a crime happened than we care about whether we can prove the crime. In cybersecurity, not having enough logging should be something along the line of negligence. > Did you prevent 845 GB of data being found by a black hat or did you find that data because of a black hat? I've seen it both ways. Some employees are diligent and go out of their way to investigate proactively. Sometimes an employee only investigates if there is a sufficiently suspicious finding. I've seen instances where the only hint that a user breached a database was a SQL query error that got logged in an application such that the app as designed couldn't generate that query.
- sosuke 6y agoThank you and thanks to the other replies. I don't often have a comment that is so full of questions and speculative thinking as this one was. Negligence makes sense in this case. Just thinking out loud now. If that were made illegal/legal would software engineers need to be state/federally certified having a license to code? Would they possibly need to carry insurance like doctors do? Curious possibilities.
- thephyber 6y ago> If that were made illegal/legal would software engineers need to be state/federally certified having a license to code? Not sure. I've certainly entertained that possibility, trying to think about the trade-offs. In essence, programming is sometimes low level machine language or high level scripting. I don't think writing formulas in Excel (or any other spreadsheet) should be limited to just certified, licensed, and bonded Software Engineers. > Would they possibly need to carry insurance like doctors do? Software in the USA is not currently considered a "product", so it has no legal requirement to carry warranty guarantees. If that legal requirement is ever changed, or if a programmer works on a product which can cause loss of life either employer indemnification in the engineer's employment contract or a professional insurance policy should be considered. That said, of all programmers, this seems like a small subset.