Live data from Hacker News

Sad reality: It's cheaper to get hacked than build strong IT defenses

theregister.co.uk

111–117 of 117 posts

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#111

Earlier quoted context omitted.

I pointed out here... https://news.ycombinator.com/item?id=12566098 ...that a few, inexpensive practices stop almost all the common methods currently. There's also frameworks and stacks that immunize web applications against common ones for them with little to no effort by developers. These fit parent's claim where you just follow basic, security advice with available tools for each category to stop many attacks. Now…

From your points: > Australia's DSD said that just patching stuff and using whitelisting would've prevented 75% of so-called APT's in their country. Throw in MAC-enabled Linux, OpenBSD, sandboxed (even physically) browsers w/ NoScript, custom apps in safe languages, VPN's by default, sanest configuration by default, and so on. Residual risk gets tiny. What I just listed barely cost anything. That's a lot more invasiv…

Add this whitelisting software with your main apps on the list. Install updates when available by clicking update. Done for 75% of it. Your admin using OpenBSD or Linux install instead of something else for backend is invisible to you. The developers writing apps withbone framework or library use a different one. I'm not seeing this invasive nature of easy stuff. Straightforward.

Seems more do given the number of companies with 1-5 IT people that do stuff like this. They just care, Google tech X plus security/hardening guide, and follow the advice. Apply patches, check logs on occasion. A little less apathy goes a long way.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#112
post #98

Earlier quoted context omitted.

This analogy fails when you consider the complexities in securing a sprawling IT architecture for a massive corporation compared to putting a lock on a door. Companies like Yahoo did try to secure themselves. They were just really bad at it.

The point of the analogy is that casual negligence of even the most basic security procedures should have built-in consequences... for the negligent party.

Consequences, yes. But the parent poster was suggesting the culpability should fall on the victim, not the attacker, which is just ridiculous.

They should be fined for negligence, but that doesn't mean the attacker is somehow morally right in any way.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#113
post #74

Earlier quoted context omitted.

Solution: Make it cost the company and keep them from passing along that cost to consumers.

Oh, that sounds totally reasonable. What are you going to call the government agency which reviews the industry-wide acceptable pricing to determine what is the right price for a private business to charge consumers?

I don't think the name is the most important thing, do you?

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#114
post #98

Earlier quoted context omitted.

The point of the analogy is that casual negligence of even the most basic security procedures should have built-in consequences... for the negligent party.

Consequences, yes. But the parent poster was suggesting the culpability should fall on the victim, not the attacker, which is just ridiculous. They should be fined for negligence, but that doesn't mean the attacker is somehow morally right in any way.

Culpability can be shared, in the real world.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#115
post #114

Earlier quoted context omitted.

Consequences, yes. But the parent poster was suggesting the culpability should fall on the victim, not the attacker, which is just ridiculous. They should be fined for negligence, but that doesn't mean the attacker is somehow morally right in any way.

Culpability can be shared, in the real world.

Sure, but when it comes to blame the bulk should still belong to the intruder.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#116
post #92

Earlier quoted context omitted.

So you think that startups with hockey-stick growth should have to design systems which are impervious to extremely sophisticated criminals? That seems unlikely. Edit: also, the main risk here is password reuse. How is Yahoo supposed to estimate that and why are they on the hook for user's bad security practices?

I'm not sure how "mandatory liability insurance" gets translated into "have to design systems which are impervious."

You're forced to spend money to mitigate losses. If you can do something to decrease the losses, or the likelyhood of suffering one, then the insurance will cost less.

Re: Sad reality: It's cheaper to get hacked than build strong IT defenses

#117
post #116
post #92

Earlier quoted context omitted.

I'm not sure how "mandatory liability insurance" gets translated into "have to design systems which are impervious."

You're forced to spend money to mitigate losses. If you can do something to decrease the losses, or the likelyhood of suffering one, then the insurance will cost less.

Right, so your spending will increase up to the point where your ROI is 1:1, then you'll stop. That point will be long before you reach imperviousness.
Post reply on HN