Live data from Hacker News

Despite decades of hacking attacks, companies leave sensitive data unprotected

propublica.org

31–40 of 45 posts

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#31
post #8

Earlier quoted context omitted.

Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked

Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively? What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault?…

It also doesn't help that these frameworks are often dated and don't align with modern best practices. Shops have the choice to check the boxes and do things the dumb way or to fill out page after page after page of special exception documentation for their auditors. Most take the easy way.

And that doesn't even cover the part where PCI, SOCII, and SOX all have various bits that contradict or are not compatible with each other.

I've seen too many times where the head of security or IT or whatever picks a pre-made package off a shelf from one of the audit providers where they guarantee you will pass all of them. Then they follow it like it's law ultimately leading the swe/devop/sre groups to build out layers of shadow it/ops to actually get productive work done.

My work primarily is to jump into startups after they are acquired to make them "enterprise ready" for a bigger org and its always a unique shit show dealing with the preexisting war between their security/it orgs and their actual product development orgs.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#32
post #18
post #8

Earlier quoted context omitted.

Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively? What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault?…

>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't. Of course if…

Fines don't happen until they get caught. How long can a company go and how much can they make before they get caught? What happens to the executives? They just move on pointing to their old success numbers.

I run internal audits for a large org as part of a strike team when my company is acquiring smaller orgs. External auditors are a joke and it's incredibly easy to slip things by them. The only reason we catch stuff is because we assume full ownership as part of our takeover process and actually build and deploy product to find issues.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#33
post #9

As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…

“Damn you, masquerading as hundreds, if not thousands, of customers! How dare you steal their identities!” — Mitchell & Webb, Identity Theft ( https://www.youtube.com/watch?v=-c57WKxeELY )

Lol. This is a clever way of putting it. Actually helped me understand some of this

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#34
post #33
post #9

Earlier quoted context omitted.

“Damn you, masquerading as hundreds, if not thousands, of customers! How dare you steal their identities!” — Mitchell & Webb, Identity Theft ( https://www.youtube.com/watch?v=-c57WKxeELY )

Lol. This is a clever way of putting it. Actually helped me understand some of this

The video should be required to accompany any article about “identify theft” to raise political awareness that a business being defrauded should be the business’s problem.

Edit: the business and law enforcement/court system’s problem. But certainly not an uninvolved individual’s problem.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#35

As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…

> Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why established card companies can have very reasonable processes to cancel transactions, mark some as fraudulent, and probably why they have reversible transactions. Do they do that of their own volition, or because there's some legal requirement forcing them to?

Credit cards are heavily regulated in the USA and, yes, there is a legal requirement here.

No such requirements exists for debit cards. This is why I hate them. But from what I can tell, most people don't seem to have a problem getting fraud reversed.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#36
post #17

There's a lot of great comments in this thread pointing at different aspects of this issue. I think it's actually more complex than all of that, because while all of these things are true, it misses the primary cause of bad information security: People. At every layer of nearly every company, nobody has any understanding of information security. Where-as, as a society, we have at least a basic understanding of physic…

And then you occasionally have people who know a thing or two but their hands are tied because organizations are dysfunctional and people have no autonomy.. or worse yet, are punished for sticking their nose into things that weren't on their task list.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#37
post #18
post #8

Earlier quoted context omitted.

Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. Sure, "has firewall" is pretty effective but how do you encapsulate how it should be managed effectively? What happens when a system that was supposedly secure installed by a previous employee fails? The company's fault? How would they know? The employee's fault?…

>Because there are very few regulations that can effectively capture the intent of the rules instead of "tick boxes" that might or might not mean very much. So HIPAA fines a company up to $50,000 per patient when a data leak occurs. They don't have to regulate how to secure the data, they just have to establish a fine with teeth requiring that companies secure their data with punishment when they don't. Of course if…

Look up the cap on fines per year. It's less than $2m.

I've consulted for healthcare companies where that is a literal rounding error on their bottom line.

They. Do. Not. Care.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#38

Why treat anything serious if it doesn't impact the board? I wouldn't either if I'm in that position. For sure I'm going to hire consultants with coats made of certificates and then sleep tight. I have done what the law or insurance company wants to see and I have consultants as black sheep. What on earth do you expect me to do more? Better processes? Sure let me hire more consultants wearing suits...

You forget that the board is also full of slightly-more-official-looking guys wearing suits. Guys in suits often forget that there is more to life than appearances, and that there is a cold hard reality unaffected by spin. Ransomware is gonna ransomware regardless of how many boxes you check and how shiny your suit looks.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#39

Why treat anything serious if it doesn't impact the board? I wouldn't either if I'm in that position. For sure I'm going to hire consultants with coats made of certificates and then sleep tight. I have done what the law or insurance company wants to see and I have consultants as black sheep. What on earth do you expect me to do more? Better processes? Sure let me hire more consultants wearing suits...

You forget that the board is also full of slightly-more-official-looking guys wearing suits. Guys in suits often forget that there is more to life than appearances, and that there is a cold hard reality unaffected by spin. Ransomware is gonna ransomware regardless of how many boxes you check and how shiny your suit looks.

That's exactly what I'm trying to say. I don't have high hope for this.

Re: Despite decades of hacking attacks, companies leave sensitive data unprotected

#40
I see a lot of comments about more punishment and regulation - but that could actually backfire and cause the problem to become worse.

More penalties would raise the stakes for the data, making it far more valuable to hackers. What's the value of data which, if exposed, can cause people to go to jail or lose lots of personal wealth? A lot, especially for ransom or blackmail.

Take HIPAA data as a prime example. What is the inherent value of health data to hackers - not much, for the most part. Maybe a little value if you get some public-figure data, but who cares what prescriptions I (a nobody) am on? The primary value to hackers of health data is exactly that it is very regulated and penalties for exposure are very high. This makes it great for blackmail and ransom. So now we have tons and tons of various nonsense "security" and "privacy" hoops we have to jump through and many $B's of cost related to protecting it. How many BS privacy policies have you gotten in paper form? How many privacy liability-waivers and other such docs have you been forced to sign before every medical treatment?

The better approach is to reduce the value and quantity of this data in the first place, so that hackers won't spend as much effort trying to steal it, and when they are successful it doesn't matter as much.

What if SSN's weren't used as ID numbers everywhere? What if it were much harder to abuse credit card numbers? What if we didn't keep allowing/REQUIRING companies to store so much personal information about us in the first place?

Post reply on HN