5 ms·
This also affected people who use software for things other than businesses. People with IoT apps for their home, researchers, etc. Our field is vast and there
by bhargav 6y ago
This also affected people who use software for things other than businesses. People with IoT apps for their home, researchers, etc.
Our field is vast and there is a large variance in people just using the basics of CS and those who keep up with standards and best practices, etc.
Your statement is basically akin to someone saying that it’s fine for people to get robbed if they went out with their wallet; or worse.. killed.
- nend 6y ago>Your statement is basically akin to someone saying that it’s fine for people to get robbed if they went out with their wallet; or worse.. killed. Uhh no? The analogy would be that there's some benefit that comes from someone's wallet being destroyed, instead of stolen.
- unstatusthequo 6y agoI’d say it’s closer to leaving your wallet on the street. If you don’t care to protect it you should assume someone will fuck with it.
- hobs 6y agoJust because its offering some useful service doesn't indemnify the ownership from the bad methods they use to deliver the service. Exposing your database to the internet with default creds is not "standards and best practices" - its highly negligent, and if you are taking people's money for such a service, I have no pity for you.
- hddherman 6y agoThat's not a good argument, inexperience does not excuse exposing user data.
- petee 6y agoIf you can't or don't know how to secure it, it shouldn't be online. My argument is more akin to a child learning not to leave their bike unattended on a city street corner overnight. I can come by pick up the bike, and tell you the dangers, but there's only one real way to learn. And clearly my opinion isn't even close to comparison with somebody being killed in a robbery.
- HomeDeLaPot 6y agoYeah. I don't care if some big business loses their Elasticsearch data and their site stops working until they get it secured and re-hydrated with data from their relational database. Good, they learned a lesson. But I would feel bad if someone's small business had to shut down or lose a bunch of money because they lost all their customer data. I'd feel bad if someone lost all the data they'd been using for a personal project. If they didn't have backups and proper security, shame on them, but ideally they would be contacted and given advice. Ideally, their data would only be deleted if the effect would be minimal. On the other hand, if this is something that happens consistently -- all unsecured databases get deleted immediately -- maybe the data would be stolen less and everyone would have to learn their lesson early...
- acdha 6y agoI’d feel bad if someone’s hobby project was deleted. Small businesses losing customer data is only slightly more sympathetic than people getting sick because they didn’t think the health code applied to them. If you collect it, you need to be responsible for keeping it safe. Anything affected by this is already exposed and has to be assumed to have been breached.
- Wowfunhappy 6y agoWhat if it was a small business's inventory data rather than customer data? Seems to me, there are a lot of things businesses could store in a database which don't necessarily need to be private, or which at worst won't harm anyone other than the database creator if exposed.
- bhawks 6y agoThis is more akin to a person knowing the basics of driving a car but not which side of the road to use or what to do at a traffic light. They are a danger to themselves and others, the others in this case being the users of whatever services the unsecured databases provide. My sympathy for people learning the basics of our field and missing a few points stops when others are harmed.
- pizza234 6y agoAlthough the parent's analogy is arguably flawed, there's a very good point in the fact that there are users who are not involved in the implementation of the service - "People with IoT apps for their home". They're not drivers, to follow the driving analogy. It's unrealistic to expect that the population at large starts to pay a significant attention, in particular because the services/gadgets are a black box. How does one know if a device is safe? A layman surely can't; even somebody who's "just a dev" likely can't. Given the large-scale nature, probably some form of regulation would be the most realistic mitigation. Following the analogy, such users are taxi clients, and for similar reasons, taxis are regulated. With that in mind, certainly the engineering side of the equation should be held accountable. But it seems that the market is not punishing it at all.
- bhargav 6y agoYup. My point is some people might not even know that their database is accessible from the web lol. It’s pretty easy to follow a tutorial or get something OOTB that’s not secure, so we shouldn’t be saying we’re glad this happened. Even if it’s big businesses, what if said businesses were storing important data such as health records? I think the learn by failing is a good mentality but was hoping we can be mindful of the fact that this harms more than just the “big bad man” Edit: Addendum for a more thoughtful discussion, it would be great if these databases and tools provided some default security OOTB requiring no configuration whatsoever. Example: rather than creating user and password with root, is rather have some CMS site generate a random one!
- fiddlerwoaroof 6y agoIoT is unlikely to be affected, unless the device goes out of its way to expose its database via upnp
- GekkePrutser 6y agoJust putting a password on a database is more than a 'standard', it's truly common sense. Really, even a beginner should think of this. Otherwise they shouldn't be messing with this stuff. And if they do get 'meowed', lesson well deserved.
- tomc1985 6y agoWould you send or let people venture out into the Wild West in its heyday unprepared and unequipped? Why aren't we applying this same logic to CS topics? It's a vast world out there and much of it's out to get you. Be prepared or die.