Live data from Hacker News

Sad reality: It's cheaper to get hacked than build strong IT defenses

theregister.co.uk

101–110 of 117 posts

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#101

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

Because there are significant external costs that the entities sloppily handling records don't have to pay but the rest of us do. Presumably that's the reference they had in mind when they referred to the "Ford Pinto formula," since it's unlikely customers would have agreed that it was better to have cars that had some risk of blowing up and killing them so Ford could make more money.

All products carry some risk, and all companies calculate the risk vs the cost of mitigation. It's impossible to make any product if safety trumps everything else.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#102
post #81

Earlier quoted context omitted.

It's not possible to 100% guarantee that data will never leak, but it's entirely possible to 100% guarantee that the company will cover the full costs of a leak. If that was somehow a legal requirement, everyone would go out and buy insurance for it and then life would go on, probably with additional emphasis on security.

I have a different position on that. My perspective is that if a company doesn't act negligent, follows all legal procedures and industry standards regarding data security then why should it be made to pay for damages caused by a third party. It didn't cause the damage, it's been the criminals who did that. They should be held accountable for this.

Is it also your position that the current legal standards for what constitutes negligence when handling customer information are appropriate?

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#103

Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…

The problem is that this isn't about saving money overall . Users pay the primary costs of the company's security errors, so it's a moral hazard problem. Right now, companies that lose data don't pay any costs at all until afterwards, and those costs are usually minimal. The reputational damage is reduced because no one knows until (well) after the breach, and any financial info lost is consumer credit cards rather t…

> The problem is that this isn't about saving money _overall_.

It hasn't been shown to be otherwise either though.

> companies that lose data don't pay any costs at all until afterwards

Because we don't know what they should pay. We need reliable research that nails down how much a security breach costs society, and until have it, it's impossible to provide companies with the right incentives.

Note that the cost should depend on the circumstances. For example, if Google or Facebook has a major breach, it would probably have a bigger impact (on a per-user basis) than a small service.

If you just impose a uniform per-user cost for data breaches, then you're essentially giving larger services an unfair competitive advantage.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#104
post #74

"Cheaper" is not including the full cost of compromised data. Compromises don't only affect companies' bottom lines, but also those who were compromised. The costs to individuals are undoubtedly much harder to quantify.

Solution: Make it cost the company and keep them from passing along that cost to consumers.

Oh, that sounds totally reasonable. What are you going to call the government agency which reviews the industry-wide acceptable pricing to determine what is the right price for a private business to charge consumers?

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#105

Earlier quoted context omitted.

I get what you mean, but poor defense ain't no excuse to hack the hell out of company, neither legally nor morally. plus i don't buy the notion that some teenager had no clue what he was doing would harm other's livehood (if yes, then he should go through psychiatric evaluation). if I don't put 3m electric fence with automatic sentry guns around my whole hypothetical house and land, does it mean everybody is automati…

I am not sure the analogy is very accurate. You do not advertise your house as a place where other people can come and freely store their valuables and then take it out as they please. If you did, there is a name for what you have built: a bank. And you can be pretty sure people then will not have any issues with whatever security measures you take. Most of all, your cost of security installation is now covered by ot…

> I am not sure the analogy is very accurate. You do not advertise your house as a place where other people can come and freely store their valuables and then take it out as they please.

Your bank doesn't have weapons turrets in its physical branches, either.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#106

Earlier quoted context omitted.

Because there are significant external costs that the entities sloppily handling records don't have to pay but the rest of us do. Presumably that's the reference they had in mind when they referred to the "Ford Pinto formula," since it's unlikely customers would have agreed that it was better to have cars that had some risk of blowing up and killing them so Ford could make more money.

All products carry some risk, and all companies calculate the risk vs the cost of mitigation. It's impossible to make any product if safety trumps everything else.

OK, but if it costs you tens of thousands of dollars when some bad thing happens and it costs the vendor nothing they're likely not actually making a reasonable trade-off; they're just leaving you out to dry.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#107
post #14
post #7

I am sick of seeing headlines about teenager hacker being put in jail. It's not because they are geniuses it's because of poor IT defense. The companies should be severely fined for criminal negligence.

And I get downvoted for saying self-driving car companies should be fined signficant amounts of money for both car accidents due to poor self-driving software capabilities but also for security breaches. What if it's "cheaper" for the car companies to let the cars crash than adopt stronger security? You may think that there's no way a recall would be worth it, but we're already seeing companies such as Tesla "fix" th…

You looked at PR and outrage but not a major cost: class-action lawsuits. It's what made Pinto risk assessment so wrong.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#109
post #81

Earlier quoted context omitted.

It's not possible to 100% guarantee that data will never leak, but it's entirely possible to 100% guarantee that the company will cover the full costs of a leak. If that was somehow a legal requirement, everyone would go out and buy insurance for it and then life would go on, probably with additional emphasis on security.

I have a different position on that. My perspective is that if a company doesn't act negligent, follows all legal procedures and industry standards regarding data security then why should it be made to pay for damages caused by a third party. It didn't cause the damage, it's been the criminals who did that. They should be held accountable for this.

Companies seem to hold on to extra data because, "why not?" Previously, they were limited by sorting and storing physical documents. Let's say you changed your address. In the past I imagine most companies would update their file (discarding the old address, because that would cause confusion) and nowadays I can see companies keeping the old one around because it might be useful later.

I would like a scenario where companies choose not to store data not immediately useful to them. They already have incentives to store old data (it's cheap, audits, monetizing later, direct advertising, etc). The best tool I can think of is liability.

I don't think the balance between companies and individuals are always equal. If I want to sign up for cable TV I have to agree to their contract (I don't get to negotiate terms), which commonly includes; giving them your birthdate or social security number, giving up the ability to sue by agreeing to arbitration, agreeing to a 12 month contract, etc. Yes, I'm not forced to agree to that contract and can go without cable (and I can see why they need much of that info--at least upfront), but the limited alternatives (and less-than-diligent consumers) allow companies to add creepy data collection without much pushback.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#110

Earlier quoted context omitted.

The difference being -- it's easy to pay somebody else enough to get rid of Dos attacks for you, and you never have to think about it. Penetration isn't quite as easy.

I pointed out here... https://news.ycombinator.com/item?id=12566098 ...that a few, inexpensive practices stop almost all the common methods currently. There's also frameworks and stacks that immunize web applications against common ones for them with little to no effort by developers. These fit parent's claim where you just follow basic, security advice with available tools for each category to stop many attacks. Now…

From your points:

> Australia's DSD said that just patching stuff and using whitelisting would've prevented 75% of so-called APT's in their country. Throw in MAC-enabled Linux, OpenBSD, sandboxed (even physically) browsers w/ NoScript, custom apps in safe languages, VPN's by default, sanest configuration by default, and so on. Residual risk gets tiny. What I just listed barely cost anything.

That's a lot more invasive ongoing work than "add piece of hardware", or "add this DNS record".

Post reply on HN