3 ms·
> What is surprising is that you're essentially claiming clients primarily need only take a couple of measures that you imply to be trivial, so they are neglige
by staticassertion 5y ago
> What is surprising is that you're essentially claiming clients primarily need only take a couple of measures that you imply to be trivial, so they are negligent if they are breached.
Yes, you can be safe against the vast majority of threats with just a few trivial measures.
> it raises the question for even the uninformed as to why there would be a multi-billion dollar infosec industry--that includes your company--if security is as trivial as you suggest here
There are a number of reasons. While you can eliminate phishing and malware pretty trivially, and secure your organization against the vast majority of threats, there sometimes holes you'll need to poke. Things like giving HR the ability to open word docs with macros enabled, or running multiple clouds, or providing RCE as a service, etc.
But the vast majority of attacks can be stopped pretty easily. Over 95% of malware samples execute out of a single directory - blocking execution in that directory therefor breaks 95% of malware samples. Obviously there's a ton of malware left in that last 5%, but 95% isn't nothing. Why don't companies block that 95%?
> But, here you're again underscoring my point by focusing solely on the victim's "culpability" and now even claiming that they are not actual victims.
Again, individuals can be victims, corporations take on the additional responsibility when they are formed. A corporation that takes data from its users and then loses it is not the victim, the end users are.
This is legally and morally the case. When you form a corporation you literally, legally sign up for a number of responsibilities that a normal person does not have. When you take data from users you are morally (and, again, legally) signing up to protect that data.
- unclebucknasty 5y agoYour comments are summable with, "95% of attacks can be trivially thwarted by doing x, and there's other stuff we can do for the other 95%." These are unserious, self-contradicting arguments, intended to muddle the issue. You're making inane statements that suggest infosec is trivial, then slowly ceding that it's not, while pivoting back to redirecting blame to the targeted companies. The fact that corporations sign up to take on responsibility doesn't make them any less victims when they're attacked. In sum, you're going to ridiculous lengths to absolve the actual criminals here by moving blame to the victims. We should all be angry at the companies, not the actual criminals. This is a preferred misdirection technique, promulgated by Russian propagandists and the useful idiots who regurgitate them.
- staticassertion 5y ago> These are unserious, self-contradicting arguments, intended to muddle the issue. Not really? Literally 95% of Windows malware executes from one directory - the AppData directory. By enabling Applocker, built into Windows, you can block 95% of observed samples. There's no contradiction there and I'm giving very explicit, practical advice. > The fact that corporations sign up to take on responsibility doesn't make them any less victims when they're attacked. Well it kind of does. When corporations don't actually suffer due to the attacks but their end users do, it's the end users who are victims, and it's the corporation who is often at fault. Again, this is legally the case, it's why we have ISO 27001, GDPR, etc. > In sum, you're going to ridiculous lengths to absolve the actual criminals here by moving blame to the victims. We should all be angry at the companies, not the actual criminals. I don't think my lengths are ridiculous. I've mentioned two very simple policies that any corporation can start rolling out today. I'm perfectly fine blaming criminals, it's just a really silly place to start. If you want to solve geopolitical issues, power to you. But, again, we should (and do, legally) hold companies accountable to secure the data they hold. Your argument is incredibly black and white and advocates for a completely impractical response. Most corporations are not in a position to impact geopolitical incentives ie: companies can not easily budget for "make certain countries not hack us". For massive companies that can absolutely be part of their approach. But just because the hackers are at fault doesn't mean the companies hold no responsibility. As I said, individuals should never be blamed for a breach. They take on no responsibility, ethically or legally. But companies do. If you want to pretend otherwise, ok? It's denying some pretty obvious moral issues, as well as some well defined legal ones, but everyone is welcome to their own system of ethics.