3 ms·
In many of my employers over the years where security mattered, it was rarely important enough to spend much money on. One place (covered by HIPAA's rather toot
by coldcode 4y ago
In many of my employers over the years where security mattered, it was rarely important enough to spend much money on. One place (covered by HIPAA's rather toothless laws) I pointed out how insecure all of our servers & databases were (single password, known by all), and the only response I got was "we pass our audits, and anyway we trust all of our employees". Groan.
An earlier employer had a single person in charge of security for a company with 50000+ customer investment accounts. Oh and the one that was there when I started was eventually discovered to have two full time jobs, which worked because he had unlimited vacations. After that person was fired, the replacement did nothing but run a few scripts every day, and our databases did not encrypt anything, and they argued for months on whether to buy disk encryption software instead of the just encrypting credit card numbers (which meant various applications had to be modified and no one wanted to pay for that work).
So if Patreon dumped their entire security team (or just one part, it's not clear) makes me reminisce about stupidities... not much has changed.
- chasil 4y agoSecurity is a cost center right up to the day that ransomware takes the data center.