3 ms·
> Most people probably aren't inclined to deliberately target their own company. It's far more likely that there is a bad actor in the world who wants to target
by lurquer 5y ago
> Most people probably aren't inclined to deliberately target their own company. It's far more likely that there is a bad actor in the world who wants to target your company, than that there is in your company.
“Most” people are law abiding. So, I agree with the first sentence.
The second sentence, however, has little support. The universe of people who can do these types of attacks is large, but not universal. You need computer skills. Necessarily. Those with computer skills are usually already part of the industry. How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks.
In short, there are probably tens of thousands of domestic ‘bad actors’ who have (or will have in their careers) access.
Probably more.
- squiggleblaz 5y ago> The second sentence, however, has little support. Your argumentation doesn't challenge the truth of falsity of the statement, nor does it go towards challenging my conclusion. It seems to assume I've said "there are probably no internal bad actors", when I've said "securing your system against external bad actors will deal with the cases more likely to occur, and will usually be sufficient against the less likely cases". 'X is more likely than Y and preventing X mitigates Y to a tolerable level' is not equal to saying 'Y probably doesn't happen'. > How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks. Obviously the probability increases significantly with the number of employees, but I don't think that switches the probabilities. Still, the most important companies to consider are the companies which, unlike FAANGs, aren't really in a position to make independent judgement about their risk profile, but whose existence depends on their records/data. And even someone with as many employees as the US government probably has more people outside of their employ who want to target them than inside, although surely they always have some of both. I'm not sure what the relevance of your reference to computer skills is. In order to ransomware a company, as far as I know, you need to buy software off the darkweb and run it from a vulnerable location. I suppose technically that requires computer skills, but it's surely not what you mean. And the companies which are vulnerable to ransomware are not all employers of significant numbers of technically skilled people. In any case, I don't think even a gratuitous reevaluation of the probabilities significantly changes my conclusion. Even if we assumed the improbable notion that every single company in the word has a disgruntled employee and that there are no external crooks, the process of securing the system against external crooks will make it far more survivable against single internal bad actors, and the effect it has on the employees will be less likely to produce internal bad actors.
- lurquer 5y agoI don’t disagree with the general idea: there’s a large overlap in internal and external security. The entire issue just leaves me with a nagging feeling that something fundamental is being overlooked. There is something profoundly different in modern companies that didn’t exist a few years earlier; namely, a very tight concentration of data/ops/control. Whether it’s external or internal, it seems a single person can do catastrophic damage to the company AND the customers. Fifty years ago, for instance, in a typical auto plant, I doubt a single person could have truly devastated the company (short of a bomb or arson or something). Nowadays, we’re moving towards systems where not only could a single bad actor cripple the company but also cause all the cars already sold to stop. (I exaggerate a bit, but you get my point I hope... )