Oh man this is bad. >the platform operations manager at Facebook responsible for policing data breaches [...] warned senior executives at the company that its lax approach to data protection risked a major breach >One Facebook executive advised him against looking too deeply at how the data was being used, warning him: “Do you really want to see what you’ll find?” >They felt that it was better not to know. I found th…
Lol, "this is bad"? This is normal. I can give you an entire list of F500 companies I've worked at that have the same mindset. I've sat in meetings with F100 CIOs where they were given the same warning and shrugged it off. I've been asked before to turn off security monitoring systems because executives prefer to not know about vulnerabilities rather than know about them and not be able to fix them. The only thing sh…
It's a simple cost-benefit analysis.
Implementing effective security is difficult, time-consuming, and expensive. Ignoring problems costs nothing. Unless it's clear the cost of a breach is higher than the cost of security, corporations will risk a breach every single time.
The ultimate loser here is users, who bear the burden of having their data appropriated and misused. Unless the government steps in and imposes penalties on corporations on behalf of users, they'll continue merrily offloading the risks of poor data security on the general population.