Live data from Hacker News

Sad reality: It's cheaper to get hacked than build strong IT defenses

theregister.co.uk

71–80 of 117 posts

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#71
post #55

Earlier quoted context omitted.

Are you conflating DoS (something a firewall can deal with) with the kind of hacking that can penetrate a system? I'm not sure a firewall can do anything about (for example) SQL injection.

I think commenter is describing his company's operation, what attacks they were facing, and that listening to advice countered them. Commenter doesn't mention a SQL Injection or claim his case applies to anything else. Instead, merely points out that listening to professionals who understand risks of your technology and following their advise can prevent problems caused by those risks. That was my take.

The difference being -- it's easy to pay somebody else enough to get rid of Dos attacks for you, and you never have to think about it.

Penetration isn't quite as easy.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#73

"Cheaper" is not including the full cost of compromised data. Compromises don't only affect companies' bottom lines, but also those who were compromised. The costs to individuals are undoubtedly much harder to quantify.

I totally agree, but I think in this case they are saying it's cheaper for the company, which is what really matters in this context (since they're comparing it to how much the company would pay for security).

I mean, if the company's website gets hacked and your credit card data is stolen, then your card is charged $1,000, it's not the company that pays for it, right? You either talk to your bank to mark the purchase as fraudulent and get the charges reversed, or pay for it yourself (e.g. if it's a debit card).

Perhaps that's the solution though: a way to directly associate fraudulent purchases with security breaches where credit card data has been stolen, and a law that requires the breached party to pay all expenses related to that fraud. That would get all major retailers scramble to get their shit secured.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#74

"Cheaper" is not including the full cost of compromised data. Compromises don't only affect companies' bottom lines, but also those who were compromised. The costs to individuals are undoubtedly much harder to quantify.

Solution: Make it cost the company and keep them from passing along that cost to consumers.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#75
post #7

I am sick of seeing headlines about teenager hacker being put in jail. It's not because they are geniuses it's because of poor IT defense. The companies should be severely fined for criminal negligence.

I get what you mean, but poor defense ain't no excuse to hack the hell out of company, neither legally nor morally. plus i don't buy the notion that some teenager had no clue what he was doing would harm other's livehood (if yes, then he should go through psychiatric evaluation). if I don't put 3m electric fence with automatic sentry guns around my whole hypothetical house and land, does it mean everybody is automati…

If you have a swimming pool on your property, then yes you need to fence it, and fence it well. If some kid climbs that fence and drowns in your pool, kiss that property goodbye.

"Attractive Nuisance"

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#76
post #29

Earlier quoted context omitted.

I don't understand the point your trying to make. In most recent high-profile hacking cases, hackers stole customer information (including credit card numbers) from the businesses. The financial fall-out for those customers could be much worse than a physical robbery.

Stealing money can be robbing, I agree. But (this is unrelated matter) why is it possible to steal someone's money just by copying several short numbers? We have all kinds of advanced cryptography today but some payment systems still rely on transistor era technologies. And even worse, companies can track customers using CC numbers. That is wrong too. The shop should not get your name or other unique identifier when…

They didn't steal money, they stole information which could be used to get money. What you're saying is equivalent to, "They stole the design for our car's master ignition key, but since they didn't steal an actual key or a car, no harm no foul." It's not the same as stealing a car, but it's also clearly about stealing cars.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#77
post #45
post #7

I am sick of seeing headlines about teenager hacker being put in jail. It's not because they are geniuses it's because of poor IT defense. The companies should be severely fined for criminal negligence.

All that needs to happen is for a court to define poor IT security as an "Attractive Nuisance", and just generally make companies liable for their customer's information (and more broadly if possible).

Doesn't the attractive nuisance doctrine only apply to children?

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#78

Earlier quoted context omitted.

I think commenter is describing his company's operation, what attacks they were facing, and that listening to advice countered them. Commenter doesn't mention a SQL Injection or claim his case applies to anything else. Instead, merely points out that listening to professionals who understand risks of your technology and following their advise can prevent problems caused by those risks. That was my take.

The difference being -- it's easy to pay somebody else enough to get rid of Dos attacks for you, and you never have to think about it. Penetration isn't quite as easy.

Thanks - that what I was getting at.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#79
post #45

Earlier quoted context omitted.

All that needs to happen is for a court to define poor IT security as an "Attractive Nuisance", and just generally make companies liable for their customer's information (and more broadly if possible).

Doesn't the attractive nuisance doctrine only apply to children?

Yes, but then, the discussion was about "teenage hackers". More broadly though, I was just trying to get the idea across using an existing bit of common law.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#80
Now people ask why Oracle is still around? And this is the answer.

At least companies have somebody (with $$) to sue when security breach happens.

I'm really confused with following: 1) people want free services and 2) people want extra security

The above is like getting free home security system and then complaining how alarm do not work consistently.

Post reply on HN