Live data from Hacker News

Sad reality: It's cheaper to get hacked than build strong IT defenses

theregister.co.uk

91–100 of 117 posts

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#91

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

> Why is that "sad"?

It may be sad for security researchers.

Or for end-users who got their data breached, and aren't compensated fairly.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#92
post #89

Earlier quoted context omitted.

That seems pretty reasonable too. I like the idea of making the business liable regardless because it more or less automatically optimizes the combined cost of security and losses. Companies will in theory spend money on security until each dollar spent mitigates less than a dollar in losses, then stop. The trick, of course, is making sure companies estimate their risk properly and don't just screw everyone over by u…

So you think that startups with hockey-stick growth should have to design systems which are impervious to extremely sophisticated criminals? That seems unlikely. Edit: also, the main risk here is password reuse. How is Yahoo supposed to estimate that and why are they on the hook for user's bad security practices?

I'm not sure how "mandatory liability insurance" gets translated into "have to design systems which are impervious."

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#93
Has your identity been stolen? If so, were you able to determine if a large scale hack was the cause of that? Then were you able to go back and sue that company for your losses? You probably don't even have much recourse, i.e. it's cheaper for you to try to fix your own stolen identity issue than to sue the company that got hacked for renumeration.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#94

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

The problem is that this isn't about saving money overall . Users pay the primary costs of the company's security errors, so it's a moral hazard problem. Right now, companies that lose data don't pay any costs at all until afterwards, and those costs are usually minimal. The reputational damage is reduced because no one knows until (well) after the breach, and any financial info lost is consumer credit cards rather t…

The real problem is most payments & identity are pull vs push and the username is the password. If they were push, then there wouldn't be customer payment information to steal in the first place. All that would be taken would be personal shipping addresses, and those are mostly public as it is already.

Same with social security numbers and identity in general.

To solve the root cause in this case although was decided to not be good by the infrastructural organizations. Eating the fraud is cheaper than putting up barriers to payments.

If fraud liability was moved %100 to banks, payment providers and governments, we would see the problem fixed pretty quickly.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#95

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

> Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us

While it's true that nature has taken the same path for the same reasons, I don't think I'd have to look very hard for people to agree that the fact that people fall ill, sometimes seriously so, is "sad".

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#96
post #46

Earlier quoted context omitted.

Which teenager hackers? Yes, if the IT defenses are poor and they get in fair enough, another one is if they get the password list and shop around You're saying like it's ok to rob the house with only one lock as opposed to the one with several locks and security cameras

More like, if you don't put locks on your doors, maybe no one should insure you and maybe the cops shouldn't waste their time when you couldn't be bothered to even take symbolic action to protect yourself.

This analogy fails when you consider the complexities in securing a sprawling IT architecture for a massive corporation compared to putting a lock on a door.

Companies like Yahoo did try to secure themselves. They were just really bad at it.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#97
Sadder reality: This principal has been extended by many CEOs to justify not doing any security. The OP speaks of the costs of running a top-notch system. That's expensive. But please do something. Something more than just relying on your head of IT and your web designer. Read the Ashley-madison report by the canadian privacy commissioner. A supposed unicorn and they were doing nothing.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#98
post #46

Earlier quoted context omitted.

More like, if you don't put locks on your doors, maybe no one should insure you and maybe the cops shouldn't waste their time when you couldn't be bothered to even take symbolic action to protect yourself.

This analogy fails when you consider the complexities in securing a sprawling IT architecture for a massive corporation compared to putting a lock on a door. Companies like Yahoo did try to secure themselves. They were just really bad at it.

The point of the analogy is that casual negligence of even the most basic security procedures should have built-in consequences... for the negligent party.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#99
post #70

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

So what's so special about doors in Germany?

I remember seeing this in an HN thread a while ago... https://news.ycombinator.com/item?id=11822442

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#100

Earlier quoted context omitted.

When your front door isn't secure enough, you and/or your insurance company eat the loss. The point of this headline is that when Yahoo gets attack their customers are going to eat the loss, yet it's Yahoo who screwed up. That's IMO a clear example of mis-aligned incentives.

Has Yahoo acted grossly negligent? (I don't know the specifics in this case) If so then they are liable for resulting damages, if not then they didn't screw up. See, no customer is entitled to a 100% guarantee that their private data will never leak. Why? Because it is not possible to guarantee such a thing. The only thing you are entitled to is that the corporation handles your data following industry standards whic…

A guarantee does not say something will not happen. It says if it does happen, recompense will be provided.
Post reply on HN