Live data from Hacker News

Sad reality: It's cheaper to get hacked than build strong IT defenses

theregister.co.uk

61–70 of 117 posts

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#61

I found this to be true of securing my house. I had several break ins and the total cost (mostly repairs) was still far less than the cost of installing an alarm system, to speak nothing of paying for police response to false alarms.

Is there an emotional cost?

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#62
post #7

I am sick of seeing headlines about teenager hacker being put in jail. It's not because they are geniuses it's because of poor IT defense. The companies should be severely fined for criminal negligence.

An uncovered and unlocked hot tub in the back yard can be seen as an "attractive nuisance." Sure, the kid trespassed by climbing over the fence, but he wouldn't have drowned if the thing had been secured.

Sure, the hacker broke the law by hacking in, but I wouldn't have had my PII stolen if the thing had been secured.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#63
it's actually the tip of the ice burg. Given that there is no standard of care and that there is no barrier to entry to being a software developer there are a lot of things that are poorly done in this industry. Security is just one of them. With that being said I've seen a lot of secruity people go overboard with security and not take the other factors into account. IE: security people trying to prevent the CEO from having acccess to resources, or adding in policies that cost more to implement than the cost of the threat etc..

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#64
post #2

It's sad because it's true. In 2018 the data protection EU regulation gets put into play though, which might change that partially by effectively increasing the cost of losing control of data.

For Reference: https://en.m.wikipedia.org/wiki/General_Data_Protection_Regu...

This directive will drastically increase fines for data leaks in the EU.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#65

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

When your front door isn't secure enough, you and/or your insurance company eat the loss. The point of this headline is that when Yahoo gets attack their customers are going to eat the loss, yet it's Yahoo who screwed up. That's IMO a clear example of mis-aligned incentives.

Has Yahoo acted grossly negligent? (I don't know the specifics in this case) If so then they are liable for resulting damages, if not then they didn't screw up.

See, no customer is entitled to a 100% guarantee that their private data will never leak. Why? Because it is not possible to guarantee such a thing.

The only thing you are entitled to is that the corporation handles your data following industry standards which usually is at least identical but most often even better than what the law requires.

If a 100% guarantee was somehow a legal requirement then the IT industry would cease to exist the following morning.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#67
post #6

Earlier quoted context omitted.

Not sure I agree that it was Google and Yahoo's respective security architecture that caused people to switch, even tech-savvy people.

Sure. But all the things Gmail offered were things that probably looked like lousy investments to Yahoo. Why offer more storage? Why have better spam filtering? Why have better security? It all costs money!!! The point is only looking at actual cost, not opportunity cost.

Yep. Good clarification.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#68
I think this article is making a decent point but with bad data. We know of many cases where the cost of insecurity drastically outweighed the cost of basic security. The most obvious is banking where no security would drain all their money. So, they combine preventing, detection, auditing, and computers hackers can't afford to keep losses manageable. Another example on putting a number on it is the Target hit that, in last article I read, was something like $100+ million in losses. Lets not even get to scenario where they start targeting power plants or industrial equipment whose management foolishly connected to net.

It also helps to look at the other end: minimum cost to stop most problems. Australia's DSD said that just patching stuff and using whitelisting would've prevented 75% of so-called APT's in their country. Throw in MAC-enabled Linux, OpenBSD, sandboxed (even physically) browsers w/ NoScript, custom apps in safe languages, VPN's by default, sanest configuration by default, and so on. Residual risk gets tiny. What I just listed barely cost anything. Apathy, which the article acknowledges, is only explanation.

A nice example was Playstation Network hack. I didn't expect them to spend much on security. I also didn't expect it to come down to having no firewall (they're free) in front of an Apache server that was unpatched for six months (patches are free). That this level of negligence is even legal is the main problem.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#69
post #55

Earlier quoted context omitted.

I ran an unsuccessful game service for a while, and due to the nature of our product (custom 3D characters) we suspected to receive and did receive an incredible number of hack attempts for a pretty much unknown web service. Expecting the issue, we got a US $20K SonicWall hardware firewall of the class used by banks. Best investment ever. On four separate occasions we had DoS attacks that the SonicWall shrugged off w…

Are you conflating DoS (something a firewall can deal with) with the kind of hacking that can penetrate a system? I'm not sure a firewall can do anything about (for example) SQL injection.

I think commenter is describing his company's operation, what attacks they were facing, and that listening to advice countered them. Commenter doesn't mention a SQL Injection or claim his case applies to anything else. Instead, merely points out that listening to professionals who understand risks of your technology and following their advise can prevent problems caused by those risks. That was my take.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#70

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

So what's so special about doors in Germany?
Post reply on HN