Live data from Hacker News

Sad reality: It's cheaper to get hacked than build strong IT defenses

theregister.co.uk

1–10 of 117 posts

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#3
One reason it's true is because companies only measure actual cost, not opportunity cost. How much did it cost Yahoo to have every tech-savvy person in the world switch to Gmail because of Yahoo's lousy (and Google's excellent) security infrastructure? Where the tech-savvy go, the tech-unsavvy often follow. As they did with Gmail.

But lost revenue opportunities don't show up in the bottom line, so cost-focused managers don't think about them. And they conclude it's "cheaper" to not invest in this or that thing that their smarter competitors are doing.

"What gets measure gets managed." People think this (apocryphal) Drucker quote is advice. It is not advice. It's a warning.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#4
Yes, you notice it when you deal with sites where bad security can be costly, like on a (bit)coin exchange (i.e. Bittrex). You get an email at every successful login, 2FA is encouraged from the start, enabling the API keys requires 2FA, Google reCAPTCHA at every login, logout as soon as you close the browser, api keys with different levels of functionality, API requires SHA512 hashing of API key and API code and a time fingerprint. It's pretty refreshing to be honest.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#6

One reason it's true is because companies only measure actual cost, not opportunity cost. How much did it cost Yahoo to have every tech-savvy person in the world switch to Gmail because of Yahoo's lousy (and Google's excellent) security infrastructure? Where the tech-savvy go, the tech-unsavvy often follow. As they did with Gmail. But lost revenue opportunities don't show up in the bottom line, so cost-focused manage…

Not sure I agree that it was Google and Yahoo's respective security architecture that caused people to switch, even tech-savvy people.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#8
post #4

Yes, you notice it when you deal with sites where bad security can be costly, like on a (bit)coin exchange (i.e. Bittrex). You get an email at every successful login, 2FA is encouraged from the start, enabling the API keys requires 2FA, Google reCAPTCHA at every login, logout as soon as you close the browser, api keys with different levels of functionality, API requires SHA512 hashing of API key and API code and a ti…

Seriously? Bitfinex was the latest, greatest bitcoin business with a security breach, and they just pushed the losses onto their customers. Bad security at bitcoin exchanges does not generally affect the company itself, but the users.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#9
post #6

One reason it's true is because companies only measure actual cost, not opportunity cost. How much did it cost Yahoo to have every tech-savvy person in the world switch to Gmail because of Yahoo's lousy (and Google's excellent) security infrastructure? Where the tech-savvy go, the tech-unsavvy often follow. As they did with Gmail. But lost revenue opportunities don't show up in the bottom line, so cost-focused manage…

Not sure I agree that it was Google and Yahoo's respective security architecture that caused people to switch, even tech-savvy people.

Fully agreed. It was all about a lot of free storage space.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#10
All we have to know that it really doesn't matter to the business world despite all the drama in corporate IT over security (if that) is that Apple, Target, and Home Depot are having great quarters after their security breaches so any consumer backlash is materially ineffective even if people do care - not enough care.
Post reply on HN