3 ms·
Everyone's security is awful, as the penalty for failure is less than the expense required to make it secure. Until the former becomes higher the latter will gu
by coldcode 5y ago
Everyone's security is awful, as the penalty for failure is less than the expense required to make it secure. Until the former becomes higher the latter will guarantee insecurity rules.
- RJSquirel 5y ago>Everyone's security is awful True, but the Polaris (East Wenatchee) data center is a complete joke in every way.
- spyder 5y agoDoes the basic security scanning the hacker was doing costs hundreds of millions for big companies? Because that's the fines some big companies are getting: https://www.csoonline.com/article/3410278/the-biggest-data-breach-fines-penalties-and-settlements-so-far.html https://www.csoonline.com/article/3410278/the-biggest-data-b... or at least tens of millions in the EU thanks to GDPR: https://www.enforcementtracker.com/ https://www.enforcementtracker.com/ We understand it's nothing compared to their profits but is it nothing compared to the cost of basic security?
- ldoughty 5y agoEquifax agreed to pay 600 million, but still saw profits up 20% for the year... Sure they could have made 600 million MORE in profit, but that's still just 15% of their profits for the year.. sure they'll spend a few million in the area they need to shore up one time and wait for the next incident... It's just good for business... Invest enough to keep these incidents down to one every 5 years, pay fine, repeat.
- BrandonMarc 5y agoScanning is pretty inexpensive. Maintaining a complex system that passes the scans? That's something different altogether. If I take a clunker to a mechanic, how much will it cost me to hear everything that needs fixing? About $150. But actually performing the fixes? One order of magnitude greater - and that's if I'm very, very lucky!
- f38zf5vdt 5y agoEveryone always talks about making penalties more severe for data leaks. I have to wonder what the consequences of that would be. Bankrupting your competitor might become as easy as paying a few bitcoins to a foreign mercenary. I think better security and encryption protocols need to be developed that mitigate the severity of a single leak. Without more compartmentalization of data and more control put into the hands of users, leaks of these massive, un-encrypted databases appear inevitable.
- wyldfire 5y ago> Bankrupting your competitor might become as easy as paying a few bitcoins to a foreign mercenary. This would result in insurance policies to guarantee against that outcome. Those policies in turn would introduce both costs and practices across industries that would improve the security of all the insured (and indirectly, their customers). Unlike hiring a Rainmaker to look nice for the C-suite, imposing these costs would make sure that there's effective mitigations. Just like safety matters for your car, it would start to matter for your software.
- JumpCrisscross 5y ago> This would result in insurance policies to guarantee against that outcome. Those policies in turn would introduce both costs and practices Equifax had over $100mm of cybersecurity insurance coverage [1]. The breach cost them over $2bn, including fines. This isn't purely a motivation problem. [1] https://www.bizjournals.com/atlanta/news/2020/02/13/equifax-says-data-breach-has-cost-it-nearly-2.html https://www.bizjournals.com/atlanta/news/2020/02/13/equifax-...