8 ms·
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it
by addingnumbers 4y ago
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
- hunter2_ 4y agoI always wonder who "we" refers to in that usage, legally speaking. Does it refer only to a subset of employees / board members who are authorized to speak for the company? Because then even if someone analyzing logs sees something damning, if middle management is trained to stop that knowledge from reaching the top, then those speaking for the company can continue saying "we" didn't know it.
- lrvick 4y agoI have 100% seen this happen.
- johndhi 4y agoreally? what do you mean 'middle management is trained to keep that from getting to the top'? intentional malfeasance? where I work people are trying their best but dealing with complex systems, memories, and methods of communication. because of this, security issues are sometimes missed, sometimes poorly communicated, and sometimes poorly remediated.
- hobs 4y agoAlmost all companies operate with an extremely low level of trust and most places are blame, shame, and ultimately game the system all the way down. Hiding something often takes years to uncover and by then management has moved on, maybe even to their second company!
- t-3 4y agoProbably not 'trained' as much as 'heavily incentivized'. Nobody wants to be the messenger that gets shot for bringing bad news. Much easier to cover up and tell the big boss what they want to hear as long as you can.
- redler 4y agoIt means silos and information hiding are baked in — as a matter of corporate culture — at least in part to preserve the option of plausible deniability for statements like Twitter’s.
- NikolaNovak 4y agoI guess to poster's claim, "I have seen this happen" is an existential claim, not a universal one. Fwiw, I've ended up being "middle management" at a large company, with deep technical background, and I'm trained and incentivized to report, escalate, inform, communicate, share, and otherwise ensure its addressed up the bloody wazoo. I get slapped on the hand for not communicating / informing enough, never for communicating too much. Over 2 decades, I've never seen my executives try to cover something. "Manage the narrative", sure, but that's largely about how they craft a sentence, not about not reporting. However, I have also witnessed corporate culture in other places (as embedded consultant) where each layer is terrified of layer above, and each layer is heavily punished for reporting "bad news". They were institutionally set up to fail project deployment as risks are not escalated and they proudly plunge forward. They're not sure much top-down knowingly obstructed to hide stuff, as much as electroshock therapied that it's a bad experience. Taking the most cursory log at the most basic logs and saying "whee, no evidence of exploit!!" Would be par for the course :-/
- throwawaylinux 4y agoThis certainly happens. If you speak to a corporate lawyer about a potentially sensitive issue, they will encourage you to use the phone, don't put anything in writing, and don't tell anybody especially not higher ups in the company, until you sort things out with them first.
- kadoban 4y ago> don't tell anybody especially not higher ups in the company As a non-lawyer, that sure sounds like sketchy advice, even beyond the rest.
- throwawaylinux 4y agoHow so?
- kadoban 4y agoSeems both ethically questionable and maybe not the best strategy for the individual if they're being instructed to keep information to themselves instead of passing it up the chain in the company. Is that intended to keep just that employee responsible for whatever mess?
- throwawaylinux 4y ago> Seems both ethically questionable Right, but how so? A person or company can get into trouble with things being written down or made known to others. Having a lawyer consider it first is legally prudent and is entirely reasonable and common advice given out to any person (don't speak to police/regulator/other party/internet/newspaper/etc before consulting your lawyer). If you think that's ethically sound advice for a person, then what changes the calculus for a corporation? > and maybe not the best strategy for the individual if they're being instructed to keep information to themselves instead of passing it up the chain in the company. Is that intended to keep just that employee responsible for whatever mess? Probably less instructed to keep it to yourself, more encouraged to stick to "official" reporting channels, and then when you do that or come into contact with such issues by other means, more encouragement to use the phone. And it completely depends on what it is as to the intention I guess. Initially so that the lawyers are able to consider and advise. But sure you aren't paying the lawyer so they are only taking care of your interests so far as that coincides with the company's interests. So if you had a concern that you would be responsible for a legal problem, or are a victim of a criminal or civil legal matter from the company or another person in it, then I would say you should consider discussing that with your own lawyer.
- gonzo41 4y agoTech needs regulation like the finance industry in this regard. Regulation that can push responsibility for breaches up the chain. There must be ways to escalate and if something is seen and reported but not acted on, then liability goes upwards. CEO's in Finance and Banking do A LOT of compliance work and it does catch a lot of problems.
- antisthenes 4y ago"an absence of evidence is not evidence of absence" Isn't that taught in..uh..I dunno, middle school science class? Just because you don't see the rabbit, doesn't mean it doesn't exist.
- themitigating 4y agoNo, that's insane. That means I can just tell people you might have raped someone, I don't have any evidence but that doesn't mean it didn't happen. https://medicine.uq.edu.au/article/2019/04/you-look-do-not-find-why-absence-evidence-can-be-useful-thing# https://medicine.uq.edu.au/article/2019/04/you-look-do-not-f...
- addingnumbers 4y agoThat's why I referred to it as a psychological trick. They should be open and forthcoming about their level of confidence, instead of using the least worrying language they can offer while remaining technically correct.
- Dudeman112 4y agoIt doesn't have to be a psychological trick. Sometimes you don't actually have evidence it was exploited - at which point what are you meant to say?
- roughly 4y agoWell, “after investigating by <insert actual efforts taken here>, we were unable to find evidence it was exploited” would be a good start, as it would indicate some effort was put into disproving the hypothesis.
- posix86 4y agoI'm 100% certain they did put in actual effort. If you're so keen on knowing, there's a form at the bottom you can use to ask them.
- deleted 4y ago[deleted]
- kadoban 4y agoThen they should share a bit about what they researched and how confident they are one way or another. Seems like a fair expectation to have, to me.
- kbenson 4y agoIt provides close to nothing, because it doesn't indicate whether there was no evidence because there could be no evidence - you keep no logs - or whether there was no evidence in spite of the fact there definitely should be if it was exploited because of copious information kept that would show it.
- lewantmontreal 4y ago’We have no proof this wasn’t exploited’
- deleted 4y ago
- themitigating 4y agoNo, that's a normal statement when there's no evidence something occurred. "I have no evidence he murdered someone" As opposed to "He might have murdered someone, or not, I just don't have any evidence" "It's possible he murdered someone I don't have any evidence though" "I don't have any evidence he murdered someone but that doesn't mean he didn't, I'm just asking questions"
- diffeomorphism 4y agoThat is not a normal statement if it is your company's fault the question even came up. "We left a giant tub filled with cyanide completely unsupervised in front of our door for months. We have no evidence that it was used to murder someone." Has an entirely different sound to it, no?
- pcthrowaway 4y agoMore like the tub was filled with water and "we have no evidence it was used to drown someone (but also we didn't check for floating bodies)"
- lostcolony 4y ago"We left our gun outside, unsecured, but no one has complained they were shot with it and we didn't detect any fingerprints on it when we finally noticed it wasn't locked up properly"
- themitigating 4y agoNow you're claiming they didn't investigate properly which a completely different situation that you also don't have evidence for.
- rrix2 4y agoor: "keeping fine grained indexed API logs around for months on end is too expensive so we threw out the body with the bathwater"
- drivebycomment 4y agoSuppose Twitter did all it could to investigate and found no evidence. What would you rather have Twitter say in that case ?
- addingnumbers 4y ago"We are unable to determine if the vulnerability was exploited." How hard they looked is not of any consequence if they can't tell it wasn't exploited.
- i_s 4y agoSaying there is an absence of evidence (of a leak) isn't useful by itself unless they also indicate whether that is evidence of absence (of a leak). I.e., they should indicate whether it is likely that they would have caught it if a leak had occured (e.g., via extensive logging).
- thayne 4y agoProvide some level of detail on how they looked for evidence. "We have no evidence" could mean "we didn't bother looking for evidence", or "we looked extensively for evidence, but didn't find any." In fact, the company has an incentive not to keep logs or collect evidence specifically so they can truthfully claim they don't have any evidence of a breach
- behringer 4y agoHow many man hours they spent investigating would be good.
- criddell 4y ago"We assume it was exploited and you should too."
- cush 4y agoAbsolutely. That said, it's very very hard sometimes to prove a negative.
- intelVISA 4y agoThe database just dropped itself automagically
- asddubs 4y agoI wonder, if you destroy all the evidence this was exploited, can you still claim you don't have any evidence this was exploited? Asking for opinions from non-lawyers only please
- Lutger 4y agoTo be sure, use a clean room implementation: let IT destroy all the evidence, always. Then legal can claim 'we don't have any evidence'. source: I am not a lawyer
- procombo 4y agoWorks the same way with government. The "I am not aware of ..." is a great trick for when your organization is intentionally silod. The folks who get subpoenaed are left out of detailed info. It's a complete non-statement. I could bring up examples across both sides of the isle. It's all a big game.
- johndhi 4y agohaha. I am a lawyer so sorry, but while you might be able to claim that, you are legally and ethically obligated to also divulge the intentional spoiling of hte evidence.
- justinclift 4y agoAs if the people giving orders at some of these companies care about ethics... ;)
- Bedon292 4y agoDon't currently have? Sure. The quote says "At that time, we had no evidence" so I think that would be harder to argue. You could maybe make the case the statement means: At that specific moment we didn't have any evidence because we already destroyed it. But it certainly implies they mean they had not found any before that point in time.
- resonious 4y agoYes, potentially a euphemism for "we did not check to see if this was exploited, and thereby have no evidence it was exploited."
- harry8 4y agoIt would be a lot more convincing if they said they put a team on to it to investigate extensively and didn't find anything indicating it was exploited. Absence of evidence IS some evidence of absence if you look thoroughly. It sure isn't anything of the kind if you haven't actually tried to gather the evidence or are aware of giant holes in what you were able to gather.
- _8j50 4y agoIt's not a trick. Incident response (not vulnerability announcement) is all about evidence. If you can't prove it, it didn't happen. They can probably stil take precautionary measures though which the announcement is part of.