Live data from Hacker News

Sad reality: It's cheaper to get hacked than build strong IT defenses

theregister.co.uk

31–40 of 117 posts

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#31

One reason it's true is because companies only measure actual cost, not opportunity cost. How much did it cost Yahoo to have every tech-savvy person in the world switch to Gmail because of Yahoo's lousy (and Google's excellent) security infrastructure? Where the tech-savvy go, the tech-unsavvy often follow. As they did with Gmail. But lost revenue opportunities don't show up in the bottom line, so cost-focused manage…

Actually, it was the free space. Everyone who used Gmail didn't trust it very much and was wary about Google sharing their info, especially as it was showing ads related to your email archive.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#32
post #7

I am sick of seeing headlines about teenager hacker being put in jail. It's not because they are geniuses it's because of poor IT defense. The companies should be severely fined for criminal negligence.

I get what you mean, but poor defense ain't no excuse to hack the hell out of company, neither legally nor morally. plus i don't buy the notion that some teenager had no clue what he was doing would harm other's livehood (if yes, then he should go through psychiatric evaluation). if I don't put 3m electric fence with automatic sentry guns around my whole hypothetical house and land, does it mean everybody is automati…

Indeed but if you don't build a fence around your swimming pool and a child wanders over and drowns that is often on you. I'd like to see some fines for negligence in examples like this. Both the attacker and the victim are at fault in my opinion.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#33
Part of the issue is that legally in the U.S. a) privacy violations are usually punishable by law only if a specific non-privacy harm comes of it and b) privacy is treated as an individual right and not a societal good. If a company gets hacked and loses your credit card and bank information afaik it's punishable only if someone actually fraudulently uses the information. It's up to individuals to jointly complain about specific damages to effect changes, and for any given individual there's little incentive to make your own life difficult for vague potential benefits. Also in most cases the individual harm is quite small, even if in aggregate or viewed as a societal harm there is huge damage.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#35

Earlier quoted context omitted.

Which teenager hackers? Yes, if the IT defenses are poor and they get in fair enough, another one is if they get the password list and shop around You're saying like it's ok to rob the house with only one lock as opposed to the one with several locks and security cameras

Hacking is not the same as robbing. Hacker doesn't take anything away from you, except some reputation.

I'd say that depends on the hack. The hacks just for prestige aren't really that prevalent any more.

These days it's hack for stealing creds or money or secrets or perhaps just putting ransomeware on all the comapanies systems to get a bitcoin payment out of them...

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#36
post #7

I am sick of seeing headlines about teenager hacker being put in jail. It's not because they are geniuses it's because of poor IT defense. The companies should be severely fined for criminal negligence.

I get what you mean, but poor defense ain't no excuse to hack the hell out of company, neither legally nor morally. plus i don't buy the notion that some teenager had no clue what he was doing would harm other's livehood (if yes, then he should go through psychiatric evaluation). if I don't put 3m electric fence with automatic sentry guns around my whole hypothetical house and land, does it mean everybody is automati…

I am not sure the analogy is very accurate. You do not advertise your house as a place where other people can come and freely store their valuables and then take it out as they please.

If you did, there is a name for what you have built: a bank. And you can be pretty sure people then will not have any issues with whatever security measures you take. Most of all, your cost of security installation is now covered by other people's money, which effectively gives you very precise calculations on what exactly you can and cannot spend. You are more than free to return the money and shut down shop if you feel you are in a completely unsafe neighborhood which makes your bank impossible to run at a profit.

To stretch this point a little further, imagine you did have a bank, and your customer comes and demands to take their money out, and you say "Oops. I had just left it out here on this desk, and when I went to pee, a kid just came in and ran out with all your money. I feel bad for you, but the cost of moving the stuff back and forth between front desk and the vault would make the service unprofitable. Its not my fault, its all these children in the neighborhood who keep pranking me".

The lowered barriers to hacking, combined with an ever moving target for what constitutes good security, are genuine concerns. But as a company, you are expected to shoulder the burden of security as a precondition of making the claim that you provide a good service. One way or another, people actually pay you to take care of their data as part of the service.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#38

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

The problem is that this isn't about saving money overall. Users pay the primary costs of the company's security errors, so it's a moral hazard problem.

Right now, companies that lose data don't pay any costs at all until afterwards, and those costs are usually minimal. The reputational damage is reduced because no one knows until (well) after the breach, and any financial info lost is consumer credit cards rather than corporate accounts. Yes, users sometimes get free identity theft monitoring, but those services are quite cheap to account for the fact that they don't actually work.

More specifically, this is asymmetric information and therefore the market can't adjust for it. When Yahoo loses my data, will my passwords be salted and well-hashed? How could I possibly know in advance? Consumers aren't making privacy and risk choices, they're using the internet as best they can and getting repeatedly burned for it.

If you want a clear contrast, companies are enormously concerned about "whaling" attacks, and are working hard to prevent them. Those attacks take corporate money in real time, so the costs are properly factored in. Moral hazard is inherently about broken cost-benefit measurement.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#40

Earlier quoted context omitted.

I get what you mean, but poor defense ain't no excuse to hack the hell out of company, neither legally nor morally. plus i don't buy the notion that some teenager had no clue what he was doing would harm other's livehood (if yes, then he should go through psychiatric evaluation). if I don't put 3m electric fence with automatic sentry guns around my whole hypothetical house and land, does it mean everybody is automati…

I don't think the house analogy works. You don't keep other peoples stuff at your house. If you ran a storage warehouse, I'm pretty sure your customers would expect you to have adequate security. If a customer came in through the back door of my warehouse, and told me the lock doesn't work, I wouldn't punish him. I would fix the lock.

> If a customer came in through the back door of my warehouse, and told me the lock doesn't work, I wouldn't punish him. I would fix the lock.

And if that same customer smashed a bunch of stuff, vandalized the walls, and stole product that was being stored in the warehouse - you'd prosecute the hell out of him... and then fix the lock.

Post reply on HN