I was a senior VP of tech at Starwood: here’s my take on the guest data breach
1–10 of 61 posts
Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#2> The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years.
It does not mean that. It means that we don't know of any exploited vulnerabilities before that point.
> If the detection tool was used prior to this September, why hadn’t the breach been detected earlier? And if the tool was not used earlier, how can they be so sure the breach occurred in 2014?
It isn't unthinkable that the new tool alerted them to a problem, and during investigation discovered evidence that the vulnerability had been abused in the past.
> It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys.
Why? The argument seems to be: the primary encryption key is important, and thus will be most carefully guarded, so it is unthinkable that it would actually be exposed.
Ultimately the article strikes me as an article written by someone who has a beef with Marriott, and he ends noting that it's possible that the breach occurred not due to issues with design, but due to the layoffs of Starwood's technical staff.
Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#3Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#4I mean, that seems very easy to imagine? Just last year Wannacry exposed an RCE exploit in Windows that has been present since at least Windows XP (https://docs.microsoft.com/en-us/security-updates/securitybu...). And there are orders of magnitude more people looking for exploits in Windows than Marriott's internal systems. I don't find this article particularly credible.
Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#5Hell, Hilton allowed for 4-digit numeric passwords until a few years ago.
Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#6Edit: this article has gotten a lot more upvotes than I would expect if something this quality, is there something about it I'm missing that makes it particularly insightful?
Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#7I was reasonably sold on what was being said until that comment. Impossible is a strong word to use when it comes to computer security. It seems that everyone who has claimed that there system is unhackable, always ends up being hacked.
Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#8Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#9This article seems full of points that a lay person might nod along with, yet don't hold up to scrutiny. > The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years. It does not mean that. It means that we don't know of any exploited vulnerabilities before that point. > If the detection tool was used prior to this September, why…
I agree with your first several points, but a lay-off beef is unlikely since the author hasn’t worked for Starwood in over a decade.
Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach
#10> It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys. I was reasonably sold on what was being said until that comment. Impossible is a strong word to use when it comes to computer security. It seems that everyone who has claimed that there system is unhackable, always ends up being hacked.