Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

61–70 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#61

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Is it the same for small and medium sized company though? We spend quite a lot on infosec with the premise that a breach could put us out of business since we can't afford to tarnish our reputation and loose key clients. Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and b…

My post is obviously sardonic to some extent, there are lots of situations where you need to worry about security.

I think I'm just more angry about these "too big to fail" companies that are apparently immune from any oversight or consequence today. We should really just convert the FTC building into a homeless shelter and fire all employees, they have done absolutely nothing for decades so this would be great way to actually use the space effectively.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#62

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

The consequence is I won't use them and as much as possible others won't either. It's not the same as no consequence, but I get what you mean. The government plays so nicely with business that we shouldn't expect even a day's worth of business profits in related fines.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#63

In my opinion organizations still don't rely enough on "defense in depth" techniques to protect sensitive data. Breaching the WAF and gaining access to S3 files shouldn't suffice to gain access to the raw data. Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized. I couldn't find information about the exact use case of the data but as it was stored in S3 I w…

I find that in large organizations, business only cares about business. Maybe because they can't be bothered with IT or security or any of the geeky disciplines. I'm pretty sure it's all about soft skills: they just can't handle dealing with folks that lack soft skills and those geeky, nerdy folks running the technology stack lack soft skills and only ever ask to spend money ...

If you, tech geek, learn enough to speak well to The Business, you have another challenge: the market is at a place where incentives matter. You can articulate, in the right language, the need for cleaning up the company security posture, but you can't articulate an incentive. User can't sue because the ToS says 'mediation;' There's no regulatory agency that will really threaten our profits - we can afford a $10MM fine when they get around to levying such after three years of investigation ... what's the incentive to spend half a million dollars this year on additional employees and licenses when that's money destined for high-level bonuses this year, and by the time that fine arrives, this executive team will have moved on?

>In my opinion organizations still don't rely enough on "defense in depth" techniques...

This flies in the face of 'easy money.' 'Easy' meaning we, The Business, comprehend the purpose of a particular budget line item. Spending money is bad. But spending money in some places is a necessary evil, and only acceptable when it is in a place that is directly reflected in the price to the customer. Acquiring, manufacturing, assembling parts in the final product? Fine. Marketing to acquire a customer? Sure. Attaining regulatory approvals? Bah, ok. After we've articulated the costs and padded an acceptable margin, the only thing left is the self-congratulatory bonuses for executives!

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#64

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

The consequence is I won't use them and as much as possible others won't either. It's not the same as no consequence, but I get what you mean. The government plays so nicely with business that we shouldn't expect even a day's worth of business profits in related fines.

I wish I had the option of not using Equifax (or Experian, or Transunion, or the secret telecom one), but apparently there is no way to opt out of all your most personal data being the product they sell in these private systems.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#65

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

The consequence is I won't use them and as much as possible others won't either. It's not the same as no consequence, but I get what you mean. The government plays so nicely with business that we shouldn't expect even a day's worth of business profits in related fines.

> The consequence is I won't use them...

Yeah, i fully agree...But, what about orgs like equifax where you and I are not really given a choice about their role in our lives? Even before all the shenanigans around equifax, would i have willingly allowed equifax into my life? Heck no! So, while i 100% agree that we should vote with our wallets/purses, sometimes that isn't enough...and that makes me a sad panda.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#66
post #23

Earlier quoted context omitted.

For many, it's a goal to avoid having a national ID, for privacy-from-the-government reasons. The ACLU has a decent writeup about the issue: https://www.aclu.org/other/5-problems-national-id-cards

Similar to constant surveillance, the psychological implications of mandatory ID are horrifying. It tips the scale from "You are born free, but you must fulfill certain obligations to cooperate with others" to "You exist first and foremost through the lens of the government. You are not permitted to live outside the bureaucratic abstraction of you."

Go cry about it to Rousseau. If you want to continue enjoy the benefits of a modern society, to some small degree, you are going to have to play its little games.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#67

Earlier quoted context omitted.

Similar to constant surveillance, the psychological implications of mandatory ID are horrifying. It tips the scale from "You are born free, but you must fulfill certain obligations to cooperate with others" to "You exist first and foremost through the lens of the government. You are not permitted to live outside the bureaucratic abstraction of you."

Well then easy solution: you refrain from opting in into personal ID cards, but you're responsible for all fraudular and other activity that is done under your name and could have been prevented by having an ID card lock down your identity.

Holding victims civilly liable for fraud is not a fair or liberal alternative to government monitoring. Should I also have no recourse when my house is burglarized if I fail to install cameras that send a feed to the police?

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#68

Earlier quoted context omitted.

Is it the same for small and medium sized company though? We spend quite a lot on infosec with the premise that a breach could put us out of business since we can't afford to tarnish our reputation and loose key clients. Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and b…

My post is obviously sardonic to some extent, there are lots of situations where you need to worry about security. I think I'm just more angry about these "too big to fail" companies that are apparently immune from any oversight or consequence today. We should really just convert the FTC building into a homeless shelter and fire all employees, they have done absolutely nothing for decades so this would be great way t…

Did nothing? Oh no, don't forget the great service to the nation represented by the recently approved T and Sprint merger!

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#69

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

The consequence is I won't use them and as much as possible others won't either. It's not the same as no consequence, but I get what you mean. The government plays so nicely with business that we shouldn't expect even a day's worth of business profits in related fines.

I am pretty sure the vast majority of people don't even know about these breaches, and even if they do it's news that passes them by quickly. Maybe a rant or two on Facebook and then onto the next thing. Almost everyone will continue to use their Capital One credit card and the company will barely see a blip in their revenue.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#70

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?
Post reply on HN