4 ms·
The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally
by lumb63 2y ago
The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about.
Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing. If consumers really find value in that, then they will preferentially deal with that company, and other companies will follow suit.
- advael 2y agoNonsense. The people who should hold responsibility are the people who have decision-making power and derive financial benefit from these choices. A rank-and-file employee is a scapegoat given the incentives at play in the system, even if they nominally wrote the vulnerable code
- pjbeam 2y agoMy read of responsible people are corporate officers and executives--people who actually choose what to work on and are substantially rewarded by the corporation.
- packetlost 2y agoNo, the people whose name is attached to budget decisions and higher level company direction that leads to this are the ones who are responsible.
- eldaisfish 2y agothis is already an established principle in other engineering fields. If a civil engineer screws up and a building collapses, both that engineer and the engineering firm are liable. Why should the software industry be any different?
- globalnode 2y agobecause software developers aren't engineers? -- elephant in the room.
- realengineer123 2y agohuh thats strange because I have a BSE and graduated from engineering school. Sure the history major bootcamp grads arent real engineers and we need to weed them out of the industry but there are some of us who are actually real engineers
- harimau777 2y agoI think the issue isn't so much the programmers who aren't engineers as it is the managers who don't treat programmers like engineers.
- rurban 2y agoSome call themselves Hackers, they love to bypass processes. And some call themselves code monkeys, they know how to follow orders, but have no incentives at all to think by themselves for proper security. Only a tiny fraction call themselves engineers. I favor non-licensed free professions, but if you're free you should be able to follow best practices and be able to think for yourself.
- harimau777 2y agoWhen I was working in a (non-software) engineering role, when I raised a technical concern it was taken seriously. As a software engineer, when I raise a technical concern it is brushed off and it I push it then my job is at risk.
- Buttons840 2y agoThis reminds me of the story where someone accidentally deletes the database and there are no backups. Who's at fault? The individual IT employee who made a mistake, or the entire organization (especially leaders) who created a situation where one person could delete the database and there are no backups?
- xyzzy123 2y agoThere is a whole field devoted to this called governance.
- zarathustreal 2y agoI’m baffled that anyone is even asking the question.. Anyone reading this, if you are of the “well the employee whole typed the command is to blame!” opinion, could you please reply to this comment? I need to know what you think the purpose of a hierarchy is in the workplace. ..needless to say, responsibility for your direct reports is yours. If they fuck up, you fucked up. You have the choice to hire and fire at will. You choose who has access to take chances. You own the wins and the losses. If you’re a good leader you redistribute the wins and dissolve the losses. It’s the entire job. It’s 2024. There are no kings or dictators in the workplace.
- lolinder 2y agoIt's a rhetorical question that's effective because the answer is obvious.
- steelframe 2y agoYou would think so, but one time an undergraduate IT guy in my school's computer lab essentially ran an `rm -rf` on all the students' home directories 2 weeks from the end of the semester. It turns out the lab's backups weren't working. The email from the department was pretty quick to throw that kid under the bus.
- fragmede 2y ago
- jonahx 2y ago> The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. This isn't what's being suggested. Higher ups set the incentive structures that result in dwindling security resources. If their ass is on the line, they will actually listen to the developers and security experts telling them they are vulnerable, instead of brushing them off to divert resources that boost the reports which determine their bonuses.
- timr 2y ago> Higher ups set the incentive structures that result in dwindling security resources. What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time. I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect. > If their ass is on the line, they will actually listen to the developers and security experts telling them they are vulnerable, instead of brushing them off to divert resources that boost the reports which determine their bonuses. Again, why are you making this assumption? But let's say, for the sake of argument, that you're right. Now we go implement some draconian, top-down "you must be secure or the C-suite goes to jail" mandate. Corporations, out of fear of liability and prosecution, lock up tight, and refuse any and all changes that might undermine their security posture. Nobody builds anything new, because why take a risk? Expensive "security expert" consultants start appearing out of nowhere to help with "compliance" with the new rule, and companies pay for them -- because it provides a veil of responsibility for the company, even if the consultant is useless. Worse, a certain percentage of these "experts" will be hucksters (or more likely: morons) themselves, and will always tell people that "they are vulnerable", because that essentially ensures a payday. You can't prove that a system is "secure", so who can say otherwise? If you doubt that any of this is plausible, I suggest you take a hard look at our existing top-down security rules (e.g. ISO 27000, HIPAA, GDPR, PCI DSS, NIST SP 800-88 and SOC2, just to name a few) and the bureaucratic industrial complex that has erupted around them, and ask yourself it these things actually make you safer. I guarantee that AT&T was "compliant" by any conventional IT standard with these, employed an army of IT staff to document said compliance, and otherwise invested a huge amount of money in that kind of performative nonsense. Because that's what every company does. But they still got owned.
- dredmorbius 2y agoDirect liability to the front line / middle management which is cleared in exchange for defined levels of cooperation with criminal, regulatory, and civil investigations aimed at landing higher-ups would be a useful development.
- ssahoo 2y ago1. Absolute carelessness of customer data. 2. Nothing to no consequence to the executives. 3. Lawlessness of such events. Very poor consumer protection laws in this country. 4. Cybersecurity illiterate leadership making cybersecurity decisions. 5. Investing absolute little in Cybersecurity to meet bare-minimum standards. 6. Or all of the above?
- bastawhiz 2y agoAT&T bought back a ton of shares of its own stock in March. It's likely that shareholders won't feel the effect of this security breach because of those buybacks (over a medium term time window). How about instead of even more meaningless standards without teeth that don't affect the people pushing for profits over essentials like security, regulators impose punishments that actually affect the investors that ultimately create these perverse incentives in the first place? Nobody should be profiting off of a company that does wrong by over a hundred million people.