Earlier quoted context omitted.
People right here on HN advocate against start-ups taking security seriously because it slows them down. Really bugs me.
That's standard issue advice. "No company ever failed because of a security breach."
FTC says Uber took a wrong turn with misleading privacy, security promises
21–30 of 30 posts
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#22Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#23Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#24Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#25This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…
Security is much harder than it needs to be currently. Every time I deal with an OpenSSL error I die a little inside. We have scam "security researchers" distracting us on Twitter with spurious reports every week.
Asking people to "think more" is a lost cause. We need better tools that make it easier to solve problems in the critical path that encourage more secure defaults than the last ones did. Most other solutions are unlikely to make an impact.
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#26According to the General Data Protection Regulation (2016/679). Appart from regular audits you may run into the following consequences :
a fine up to 20000000 EUR or up to 4% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever is greater (Article 83, Paragraph 5 & 6[18]).
Ask companies like Microsoft, Volkswagen, Renault, Daimler or Google and they can you assure you that the responible entities don't look kindly at corporate bullshit PR statements, which the likes of Uber seem so fond of.
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#27This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…
I've done InfoSec for a bunch of startups, none seem to grasp the importance of security by design and how it can play an integral role in the business. It's exhausting to have to battle a neon-haired developer that wants to just write code (rightfully so,) not following a process or standards often engaging in arguments just to be right. Imagine one person going asking an entire engineering org to create security pr…
"We take security seriously"
Why would such a statement legally cover your ass? From a legal perspective it sounds as dubious as warnings on a Truck "Stay back 10 metres. Truck is not responsible for damage"Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#28This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#29Earlier quoted context omitted.
I've done InfoSec for a bunch of startups, none seem to grasp the importance of security by design and how it can play an integral role in the business. It's exhausting to have to battle a neon-haired developer that wants to just write code (rightfully so,) not following a process or standards often engaging in arguments just to be right. Imagine one person going asking an entire engineering org to create security pr…
I certainly agree with your comment, since it reflects my experience in a lot of cases. But "We take security seriously" Why would such a statement legally cover your ass? From a legal perspective it sounds as dubious as warnings on a Truck "Stay back 10 metres. Truck is not responsible for damage"
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#30It may be a good idea to not pull such a shitty in an EU country from May 2018. According to the General Data Protection Regulation (2016/679). Appart from regular audits you may run into the following consequences : a fine up to 20000000 EUR or up to 4% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever is greater (Article 83, Paragraph 5 & 6[18]). Ask companies like…
The fine is interesting because it is easy to minimize by creating a subsidiary per country. That very effectively shields annual worldwide turnover.