Live data from Hacker News

I was a senior VP of tech at Starwood: here’s my take on the guest data breach

phocuswire.com

11–20 of 61 posts

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#11

> It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys. I was reasonably sold on what was being said until that comment. Impossible is a strong word to use when it comes to computer security. It seems that everyone who has claimed that there system is unhackable, always ends up being hacked.

He said 'almost impossible'. Big difference.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#12
"The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years.

It is difficult to imagine how an architectural or platform vulnerability would not have been discovered or exploited sooner."

Not really. There's been vulnerabilities that have been out in the wild for quite some time and took years to be found. Sometimes it just comes down to luck/what people are trying to exploit.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#13
The article he wrote about Marriott's choice to continue using its z/TPF based platform over migrating to Starwood is also telling.

https://www.linkedin.com/pulse/marriottstarwood-back-future-...

See this quote "To better understand the resulting Starwood’s technology compared to industry legacy systems, think Tesla Model S versus a gas-guzzling 1975 Buick Electra.

Then along came Marriott . . .

When Marriott announced its interest in acquiring Starwood, one would have believed that they factored in a $500 million Starwood IP technology value within their $13.6 Billion offer, and that they would have been salivating at the prospect of having their hands on the fruits of the multi-year transformation experience this IP represented. After all, while stable as a rock, Marriott’s own system today centers around 1970’s Mainframe TPF technology (MARSHA) suitably kept current via the judicious use of the scotch-tape and wires represented by a cornucopia of front-end gateways and the labor intense support of inflexible legacy code, eclectic data bases, hard-coded interfaces, and a veritable zoo of different property management systems crying for better integration. "

It reads as sour-grapes to me.

If you wanna read more about MARSHA - this seems to be a good source: http://ibmsystemsmag.com/mainframe/casestudies/miscellaneous...

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#14

This article seems full of points that a lay person might nod along with, yet don't hold up to scrutiny. > The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years. It does not mean that. It means that we don't know of any exploited vulnerabilities before that point. > If the detection tool was used prior to this September, why…

> It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys.

I worked some place where lots data was encrypted with a key. The key hadn't changed in months - at least 6 months by the time I found it. I was told this same key would be used to encrypt web session data in a cookie. There were more than a dozen people who I knew had access to the key, and another 5 had come and gone (and had had access to the same key) in the previous 6 months.

I know not all companies are run like that, but I suspect it's closer to the norm. Even in places where they want to be more secure, enforcing security policies often becomes an after thought to more important tasks (in places I've seen/worked).

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#15

> It is almost impossible to imagine a scenario in which an external hacker is able to gain access to the primary encryption keys. I was reasonably sold on what was being said until that comment. Impossible is a strong word to use when it comes to computer security. It seems that everyone who has claimed that there system is unhackable, always ends up being hacked.

He said 'almost impossible'. Big difference.

He said almost impossible to imagine. It really was an extremely hyperbolic statement. I've never done security work but I've helped develop plans for when primary and secondary keys are stolen. It's something that should have been imagined, not "almost impossible to imagine".

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#17
Worth pointing out that at the time of this guy's tenure, and for many years afterwards, the way you authenticated yourself while booking a rewards reservation with SPG via the phone was to verbally tell the agent your online password. Like, WTF.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#19

This article seems full of points that a lay person might nod along with, yet don't hold up to scrutiny. > The fact is, if we accept Marriott’s statement that the breach began in 2014, the system would already have been operating securely for five years. It does not mean that. It means that we don't know of any exploited vulnerabilities before that point. > If the detection tool was used prior to this September, why…

I think for most companies convenience trumps security. Like the current workplace is first I worked @ were keys for signing are stored in a special secure location on air gaped systems.

Re: I was a senior VP of tech at Starwood: here’s my take on the guest data breach

#20
post #6

He seemed to say the database wouldn't have 500 million records in it at a time since they are deleted but that seems irrelevant with how the breach took place over 4 years. Anyway the article seems to be just speculation, which is disappointing. Edit: this article has gotten a lot more upvotes than I would expect if something this quality, is there something about it I'm missing that makes it particularly insightful…

This whole article reads to me like an SVP who doesn't actually understand technology and security (which is definitely not uncommon).
Post reply on HN