6 ms·
Unless you’re a valuable or high clearance entity, all of this stuff seems like adults having a fun pretend make believe time. Like that neighbor in a nice part
by abc-1 2y ago
Unless you’re a valuable or high clearance entity, all of this stuff seems like adults having a fun pretend make believe time. Like that neighbor in a nice part of town who owns multiple guns and has a security system set up to protect his maybe… $2k worth of jewelry. And if you say stuff like this, there’s always that one guy who chimes in about that one time when it actually happened for realsies and they were so glad they had their twenty layers of protection and boobytraps set up.
- vasco 2y agoValue is in the eye of the beholder. All that security does is buy peace of mind, how much you have to spend for that peace of mind is very personal. Same thing with attitudes to security of leadership teams. And if past events are indicative, there's way more leadership teams that don't give a rats ass about security than ones that do. Particularly when you're holding other people's valuables (data).
- BLKNSLVR 2y agoI initially read your first sentence as "Value is in the eye of the shareholder" and thought to myself: Hah, yeah, clever. I've now coined the phrase, accidentally. Along those lines, however, it's peace of mind against an actual intrusion, but it's also peace of mind against lawsuits for dereliction of duty, etc.
- Closi 2y agoI think it fits the idiom of "aim for the stars and you'll land on the moon". If you are the kind of company that has a focus on all aspects of security, and assumes a sophisticated actor is attacking, you will have a better chance at defending against unsophisticated actors. If you plan your security around only defending 'less-sophisticated' actors then you might quickly find one slips through the cracks.
- Puts 2y agoThe thing is though that it takes so little to just avoid things like this. If the security guard actually did his/her work and checked on unknown person coming in to the building. If the company used a password manager to share WiFi passwords (or maybe even Enterprise WPA with certificates), and make sure unused public ethernet-ports are not patched. Then these two very simple things would have made this much harder. I think the sad part is that they had probably had some security guy tell them this already but people where just making fun of him because people don't believe things they can not see - so it takes a "pretend to be SPYs charade" to make people actually care.
- b112 2y agoAnd yet they still won't care, because most people have zero interest in their job. For those that do? They're lucky, work is fun, and they often love doing the best they can at their job. So sadly for many only the threat of dismissal forces those unhappy ranks to do their job. Others have a strong work/duty ethic, and will do their best. One thing that can help overall is an entire corporate culture, where everyone is lambasted for such failures. "You saw that <security guard> wasn't doing his job, and you didn't tell anyone? You're in trouble too!", and so on.
- mschuster91 2y ago> One thing that can help overall is an entire corporate culture, where everyone is lambasted for such failures. That is precisely what you not want to do, all that breeds is a culture of hyper-paranoid ass-covering and blame deflection.
- eddyg 2y ago> because most people have zero interest in their job So. Much. This. The number of people who do “just enough” to not get fired is staggering. There is no “work ethic”. At least in the military when somebody fucks up during training the entire $GROUP gets punished. It doesn’t take long before people start taking “rules” seriously. There needs to more consequences and accountability.
- ok_dad 2y agoThe military isn’t some place you send miscreants who always misbehave, most of us wanted to do our best and your description of it is petty insulting and inaccurate. We worked together to attain a goal and fight alongside each other, not because we were beaten trained dogs.
- Aeolun 2y agoI think the implication was more that there was a lot of social pressure in the military that is absent in megacorp X
- bsmartt 2y agoi dont think anyone who is well versed in today's threats is saying to the company board members "i mean, really guys, this whole security/risk thing.. all smoke and mirrors... wasting our money on fun and games". BF as a consulting company is pretty fucking on point in my perspective, but if i were going to throw shade at a more broad swath such as the whole infosec industry from <insert stealth / yc funded AI based cyber startup> to <DARPA / Giant AntiVirus corp> I would probably diverge slightly with something more like 'there is so much snake oil, lack of proven and holistic solutions, freemium consumer products shamelessly bait and switch'ing everyday people who caught an infected flash installer online, etc, hiding amongst however many legitimate value propositions on offer that it's like ... when disaster does come, I'd reckon is more or less a coin toss as to whether our investment into CYBERHaxPreventor56000 will have delivered some portion of the price tag in returns to us. Seem like a fair response to your points?