2 ms·
> These are unserious, self-contradicting arguments, intended to muddle the issue. Not really? Literally 95% of Windows malware executes from one directory - t
by staticassertion 5y ago
> These are unserious, self-contradicting arguments, intended to muddle the issue.
Not really? Literally 95% of Windows malware executes from one directory - the AppData directory. By enabling Applocker, built into Windows, you can block 95% of observed samples. There's no contradiction there and I'm giving very explicit, practical advice.
> The fact that corporations sign up to take on responsibility doesn't make them any less victims when they're attacked.
Well it kind of does. When corporations don't actually suffer due to the attacks but their end users do, it's the end users who are victims, and it's the corporation who is often at fault. Again, this is legally the case, it's why we have ISO 27001, GDPR, etc.
> In sum, you're going to ridiculous lengths to absolve the actual criminals here by moving blame to the victims. We should all be angry at the companies, not the actual criminals.
I don't think my lengths are ridiculous. I've mentioned two very simple policies that any corporation can start rolling out today.
I'm perfectly fine blaming criminals, it's just a really silly place to start. If you want to solve geopolitical issues, power to you. But, again, we should (and do, legally) hold companies accountable to secure the data they hold.
Your argument is incredibly black and white and advocates for a completely impractical response. Most corporations are not in a position to impact geopolitical incentives ie: companies can not easily budget for "make certain countries not hack us". For massive companies that can absolutely be part of their approach.
But just because the hackers are at fault doesn't mean the companies hold no responsibility.
As I said, individuals should never be blamed for a breach. They take on no responsibility, ethically or legally. But companies do.
If you want to pretend otherwise, ok? It's denying some pretty obvious moral issues, as well as some well defined legal ones, but everyone is welcome to their own system of ethics.