4 ms·
It's hard to feel sorry for these companies when they have neglected security for so long. This outcome was inevitable, and hitting the bean counters where it
by zionic 5y ago
It's hard to feel sorry for these companies when they have neglected security for so long.
This outcome was inevitable, and hitting the bean counters where it hurts (financial bottom line) is the only way to effect change.
- danpalmer 5y agoI don't have metal bars across my windows, should they start targeting my house to force me to add them? I'm being somewhat facetious, but I want to live in a society where not being hyper focused on all forms of security at all times, and just being _safe_ is an ok way to live your life. "It's easy so we'll do it" is not a defence of this practice. The only reason the security is needed at all is because of people like this. I'm not saying security isn't important, but being bad at security is not a defence of people who take advantage of that poor security.
- trasz 5y agoCompanies are not people. If your business is taming wild animals, should you have metal bars around them?
- wastedhours 5y ago> Companies are not people. No, but employees and customers are, and they feel real, human costs as a result. Just because a management team has underfunded security is not an excuse to cause pain on other people.
- trasz 5y agoEmployees are being paid by hour, so they wouldn’t care at all. Customers - true, this might cause delays for them, if the company decided not to pay the ransom. It’s still just a delayed cost, though.
- wastedhours 5y ago> Employees are being paid by hour, so they wouldn’t care at all Sorry, but that's just not correct. It's always someone's job to clean up this mess, and that falls on individuals. If they have to clean up a stressful mess, they definitely do care. A lot. I've had to clear up messes in the past, and it severely negatively impacts my mental health. Never, ever think that it's a victimless crime. They might not feel the force of the actual crime itself, but there are most definitely employees out there where the second-order effects on their wellbeing are starkly negative. Again, for customers, you never know what those second-order effects of the delayed cost would be. I'm not going to whip up slippery slope arguments, but again, you're assuming that customer interactions with companies are all one-sided "I can do this later" kinds of interactions. We shouldn't hand-wave away bad things because they only impact some faceless "company". Companies are made up of individuals, most of whom don't want to be there, but most definitely care when they're forced to do more work by some bad actor.
- trasz 5y agoOf course it’s always somebody’s job, but that’s it: it’s their job, they are paid by an hour. There is no “more work”, it’s just the planned work will be delayed. Unless your company is exploiting you, of course.
- wastedhours 5y agoI'm not sure we're going to get much further here if you're arguing on the dichotomy of checked out employees punching a clock vs exploitation by the employer. Suffice to say, this crap has impact on real people, in the real world. To imply it's just some neutral action doesn't reflect the reality we live in.
- progman32 5y agoThe lost productivity and general _stress_ due to well-intentioned but ultimately counterproductive software being introduced by IT after a ransomware attack was the last straw for at least two highly qualified engineers I know personally. They left their employer after that. Being blocked from doing your job is highly stressful for people who are motivated by the utility of their work to society, a description which I believe fit these engineers. This is an example of direct human cost - the transformation of a desirable, fulfilling job to one less so. Now, sure, the IT dept in question could have handled this a little better. Maybe. But the presence of these advanced threats forced IT's hand here.
- nradov 5y agoThe type of society you want to live in is utterly irrelevant. Those ransomware gangs exist and there is no way to eliminate them. That is our new reality. Any business leader who is bad at security is incompetent. I wish it didn't have to be that way but whining about it won't accomplish anything.
- Spooky23 5y agoThe reason security is needed is that we have institutional methods for transferring ransom and paying for the rackets. The reason that it’s ok to have a shitty $80 lock on your front door or an unprotected window near ground level is that the value for a would be burglar to break in for a crime of opportunity is low. If you’re a well known jeweler or gun collector, you typically take other measures because you may be a target. Cryptocurrency made computer crimes profitable crimes of opportunity.
- KirillPanov 5y ago> The reason security is needed is that we have institutional methods for transferring ransom and paying for the rackets. The reason we have child pornography is that people don't need to have their photographs developed by a chemist in a photo lab anymore. The photo lab chemists would've turned them in to the cops.