Live data from Hacker News

Despite decades of hacking attacks, companies leave sensitive data unprotected

propublica.org

11–20 of 45 posts

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#11
post #8

Earlier quoted context omitted.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively? What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault?…

The same is true of legislation like SOX, which is very much a checkbox approach and has not solved everything related to financial reporting, by a longshot. But that doesn't mean regulation would be totally useless. From the article:

>The European Union has been operating under such a standard since May 2018. Known as the General Data Protection Regulation, the law requires companies to implement security measures to protect sensitive personal data and to promptly notify regulators and affected consumers when it gets compromised. Violations of the data protection rules can result in fines as high as 4% of a business’s annual worldwide sales. “You have to implement cybersecurity measures if you process personal data, and if you do not, you will have a legal problem,” said Stefan Hessel, a cybersecurity specialist in Germany at the Reuschlaw law firm.

>Such measures may in fact make it harder for hackers to ply their trade, if Pompompurin’s postings are any indication. In August he was asked on RaidForums why large collections of personal data always seem to come from the U.S. He responded: “Because its the easiest to get, other countries have load of protection laws & shit, in the US your address is basically public information no matter how hard you try not to be put on lists like this.”

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#12
Why treat anything serious if it doesn't impact the board? I wouldn't either if I'm in that position. For sure I'm going to hire consultants with coats made of certificates and then sleep tight. I have done what the law or insurance company wants to see and I have consultants as black sheep. What on earth do you expect me to do more? Better processes? Sure let me hire more consultants wearing suits...

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#14
post #8

Earlier quoted context omitted.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively? What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault?…

>there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much.

>set mandatory qualifications for IT workers/devs to ensure a base-level of security/understanding

What is it about this regulation that prevents it becoming a useless box for IT pros to check?

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#15

Why treat anything serious if it doesn't impact the board? I wouldn't either if I'm in that position. For sure I'm going to hire consultants with coats made of certificates and then sleep tight. I have done what the law or insurance company wants to see and I have consultants as black sheep. What on earth do you expect me to do more? Better processes? Sure let me hire more consultants wearing suits...

> I have done what the law or insurance company wants to see and I have consultants as black sheep.

You hit a great point. The law and insurance companies have a major impact on what companies do.

If it's illegal (and they'll get caught) or the insurance companies say "do this to get insurance or if you don't do it the insurance doesn't cover you" people will make change.

That right there is a way to bring change.

Call your gov reps.

Let's get insurance companies to put security controls into coverage policies.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#17
There's a lot of great comments in this thread pointing at different aspects of this issue. I think it's actually more complex than all of that, because while all of these things are true, it misses the primary cause of bad information security: People.

At every layer of nearly every company, nobody has any understanding of information security. Where-as, as a society, we have at least a basic understanding of physical security (we understand the gist of a lock, and use them regularly, and guard the keys), we have basically zero understanding of information security.

I've worked, in some capacity, around information security for nearly my entire career and I have found that even people I highly respect as technologists rarely have any knowledge of information security. Most of the information security side of the industry is filled with people who are trained on compliance and regulations, not on security, and they are seen as completely synonymous. Security has to be layered in order to be effective, yet that's been taken to mean several layers of different types of brightly colored middle-boxes with pretty dashboards, rather than an actual layering of security principles and a reasonable organizational posture. While these things can be tools, they are treated as solutions rather than tools that help you create a solution.

Most SWEs know next to nothing about application security. Most web devs don't even know what OWASP is, much less have any understanding of web security. Most networking folks (even those with Network Security in their title) know little about network protocols and protocol security, instead being glorified firewall rule writers. Most security architects only know about compliance and policy, nothing about actually identifying threat vectors and constructing robust organizational postures. And most executives don't care beyond what's required to comply with the law or their contractual agreements so leave it to "experts".

Most of the "experts" aren't experts. The fraud with information security isn't just what's being perpetrated by attackers, it's also what's being perpetrated by the entire information security industry, which is mostly filled with puff pieces calling themselves "experts" who don't actually understand anything about security at all, as well as vendors who sell security products that themselves may not be secure on the backend but have privileged access within their client's data environments.

All an attacker must do is find your weakest link. What you must do to protect yourself is ensure that your weakest link is stronger than anyone else's strongest link. There's a huge disparity in the effort and investment required, and it's an issue that can't simply be resolved by throwing money at it because most of the people lining up to take your money are their own sort of attacker committing their own sort of fraud.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#18
post #8

Earlier quoted context omitted.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively? What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault?…

>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much.

So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't.

Of course if congress would apply HIPAA rules to everyone's data and actually enforce it, data leaks for the most part will stop.

https://www.hipaajournal.com/what-are-the-penalties-for-hipa...

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#19

As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…

> Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why established card companies can have very reasonable processes to cancel transactions, mark some as fraudulent, and probably why they have reversible transactions.

Do they do that of their own volition, or because there's some legal requirement forcing them to?

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#20
post #15

Why treat anything serious if it doesn't impact the board? I wouldn't either if I'm in that position. For sure I'm going to hire consultants with coats made of certificates and then sleep tight. I have done what the law or insurance company wants to see and I have consultants as black sheep. What on earth do you expect me to do more? Better processes? Sure let me hire more consultants wearing suits...

> I have done what the law or insurance company wants to see and I have consultants as black sheep. You hit a great point. The law and insurance companies have a major impact on what companies do. If it's illegal (and they'll get caught) or the insurance companies say "do this to get insurance or if you don't do it the insurance doesn't cover you" people will make change. That right there is a way to bring change. Ca…

One thing I'm a bit pessimistic is that insurance policies usually bring a lot of paper work and eventually it's just certificates over certificates. But again, maybe (a big maybe) this is still better than what things are going on right now.

The best solution is for board members to have respect to their best techincal people and let them create processes best for individual companies. Sadly this is too personal and usually dies when a couple of people jump ship.

Damn, management is so hard.

Post reply on HN