4 ms·
Regardless of the impact of this breach in particular, your point still stands and is one I do share: this is a major downside to centralized identity providers
by samtho 3y ago
Regardless of the impact of this breach in particular, your point still stands and is one I do share: this is a major downside to centralized identity providers. Their existence creates a centralized point of access that all an attacker must do is bypass once for some sort of benefit.
“Security” as a practice within a company comprises of technology, process, and culture. Should one of these pillars be subverted by leadership in anyway, the organization security stance becomes crippled.
In my experience, this security kneecapping happens because some bonehead exec looks at ways to cut costs or doesn’t like having to pull their phone out to login, and decided on a layoff or loosening of policy because, “we haven’t had any problems so far, so why do we have these staff members or this highly obstructive 2FA in place?” I mean, people used to die with greater frequency in car accidents prior to seat belts, too, maybe we can eliminate those next?
- sophacles 3y ago> process, and culture Are possibly even more important than the tech. A good culture of "always report suspicious things, no one will be upset over false alarms" and a process that follows up on each report with rigor and responds to the constant stream of false positives in an engaging and encouraging way[1] catches a lot of problems before they start and/or are in the early stages. I've witnessed and heard stories of such cultures and policies catching pretty sophisticated targeted phishing campaigns with 0 breach. Similarly even for actual compromise - having a "always tell us when you suspect something, if you click on a bad link and report it when you realize it you won't get in trouble" means that breaches can be stopped early (again I've seen this prevent incidents from turning catastrophic). It's cheaper to spend a few $100K on more people to handle false positives than it is to lose millions in direct costs from a breach and even more millions on reputational loss. [1] e.g. "We examined the email and link you sent. Thank you for reporting it - it does in fact look suspicious, but in this case we've verified it's the a safe and legitimate link. Please continue sending in anything you're unsure of!"