Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…
Because there are significant external costs that the entities sloppily handling records don't have to pay but the rest of us do. Presumably that's the reference they had in mind when they referred to the "Ford Pinto formula," since it's unlikely customers would have agreed that it was better to have cars that had some risk of blowing up and killing them so Ford could make more money.
Sad reality: It's cheaper to get hacked than build strong IT defenses
101–110 of 117 posts
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#102Earlier quoted context omitted.
It's not possible to 100% guarantee that data will never leak, but it's entirely possible to 100% guarantee that the company will cover the full costs of a leak. If that was somehow a legal requirement, everyone would go out and buy insurance for it and then life would go on, probably with additional emphasis on security.
I have a different position on that. My perspective is that if a company doesn't act negligent, follows all legal procedures and industry standards regarding data security then why should it be made to pay for damages caused by a third party. It didn't cause the damage, it's been the criminals who did that. They should be held accountable for this.
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#103Why is that "sad"? Nature has gone the same path. We have basic defenses that are "on" all the time (passive immune system - nonspecific), and we have an adaptive response that reacts to what actually happens to us, which also means threats we actually encounter will be recognized and fought more quickly and better in the future. Or houses - having lived in the US, those front doors are at least an order of magnitude…
The problem is that this isn't about saving money overall . Users pay the primary costs of the company's security errors, so it's a moral hazard problem. Right now, companies that lose data don't pay any costs at all until afterwards, and those costs are usually minimal. The reputational damage is reduced because no one knows until (well) after the breach, and any financial info lost is consumer credit cards rather t…
It hasn't been shown to be otherwise either though.
> companies that lose data don't pay any costs at all until afterwards
Because we don't know what they should pay. We need reliable research that nails down how much a security breach costs society, and until have it, it's impossible to provide companies with the right incentives.
Note that the cost should depend on the circumstances. For example, if Google or Facebook has a major breach, it would probably have a bigger impact (on a per-user basis) than a small service.
If you just impose a uniform per-user cost for data breaches, then you're essentially giving larger services an unfair competitive advantage.
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#104"Cheaper" is not including the full cost of compromised data. Compromises don't only affect companies' bottom lines, but also those who were compromised. The costs to individuals are undoubtedly much harder to quantify.
Solution: Make it cost the company and keep them from passing along that cost to consumers.
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#105Earlier quoted context omitted.
I get what you mean, but poor defense ain't no excuse to hack the hell out of company, neither legally nor morally. plus i don't buy the notion that some teenager had no clue what he was doing would harm other's livehood (if yes, then he should go through psychiatric evaluation). if I don't put 3m electric fence with automatic sentry guns around my whole hypothetical house and land, does it mean everybody is automati…
I am not sure the analogy is very accurate. You do not advertise your house as a place where other people can come and freely store their valuables and then take it out as they please. If you did, there is a name for what you have built: a bank. And you can be pretty sure people then will not have any issues with whatever security measures you take. Most of all, your cost of security installation is now covered by ot…
Your bank doesn't have weapons turrets in its physical branches, either.
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#106Earlier quoted context omitted.
Because there are significant external costs that the entities sloppily handling records don't have to pay but the rest of us do. Presumably that's the reference they had in mind when they referred to the "Ford Pinto formula," since it's unlikely customers would have agreed that it was better to have cars that had some risk of blowing up and killing them so Ford could make more money.
All products carry some risk, and all companies calculate the risk vs the cost of mitigation. It's impossible to make any product if safety trumps everything else.
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#107I am sick of seeing headlines about teenager hacker being put in jail. It's not because they are geniuses it's because of poor IT defense. The companies should be severely fined for criminal negligence.
And I get downvoted for saying self-driving car companies should be fined signficant amounts of money for both car accidents due to poor self-driving software capabilities but also for security breaches. What if it's "cheaper" for the car companies to let the cars crash than adopt stronger security? You may think that there's no way a recall would be worth it, but we're already seeing companies such as Tesla "fix" th…
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#108A mountain of bureaucracy that slows down everything as much as if you had strong defenses, but is effectively as weak as bad security.
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#109Earlier quoted context omitted.
It's not possible to 100% guarantee that data will never leak, but it's entirely possible to 100% guarantee that the company will cover the full costs of a leak. If that was somehow a legal requirement, everyone would go out and buy insurance for it and then life would go on, probably with additional emphasis on security.
I have a different position on that. My perspective is that if a company doesn't act negligent, follows all legal procedures and industry standards regarding data security then why should it be made to pay for damages caused by a third party. It didn't cause the damage, it's been the criminals who did that. They should be held accountable for this.
I would like a scenario where companies choose not to store data not immediately useful to them. They already have incentives to store old data (it's cheap, audits, monetizing later, direct advertising, etc). The best tool I can think of is liability.
I don't think the balance between companies and individuals are always equal. If I want to sign up for cable TV I have to agree to their contract (I don't get to negotiate terms), which commonly includes; giving them your birthdate or social security number, giving up the ability to sue by agreeing to arbitration, agreeing to a 12 month contract, etc. Yes, I'm not forced to agree to that contract and can go without cable (and I can see why they need much of that info--at least upfront), but the limited alternatives (and less-than-diligent consumers) allow companies to add creepy data collection without much pushback.
Re: Sad reality: It's cheaper to get hacked than build strong IT defenses
#110Earlier quoted context omitted.
The difference being -- it's easy to pay somebody else enough to get rid of Dos attacks for you, and you never have to think about it. Penetration isn't quite as easy.
I pointed out here... https://news.ycombinator.com/item?id=12566098 ...that a few, inexpensive practices stop almost all the common methods currently. There's also frameworks and stacks that immunize web applications against common ones for them with little to no effort by developers. These fit parent's claim where you just follow basic, security advice with available tools for each category to stop many attacks. Now…
> Australia's DSD said that just patching stuff and using whitelisting would've prevented 75% of so-called APT's in their country. Throw in MAC-enabled Linux, OpenBSD, sandboxed (even physically) browsers w/ NoScript, custom apps in safe languages, VPN's by default, sanest configuration by default, and so on. Residual risk gets tiny. What I just listed barely cost anything.
That's a lot more invasive ongoing work than "add piece of hardware", or "add this DNS record".