Live data from Hacker News

Nobody Cares About Security

adatosystems.com

1–10 of 93 posts

Re: Nobody Cares About Security

#2
Disagree. Security isn’t just about recovery. Say you get breached. Many threat actors are well aware of global privacy laws and exfiltrate data and threaten to release it if not paid the ransom. Some go a step further to notify privacy regulators of the breach to further leverage ransom payment.

Recovery from an encryption event is great and all, but it doesn’t solve the problem of your new regulatory fine and legal problems.

Re: Nobody Cares About Security

#3

Disagree. Security isn’t just about recovery. Say you get breached. Many threat actors are well aware of global privacy laws and exfiltrate data and threaten to release it if not paid the ransom. Some go a step further to notify privacy regulators of the breach to further leverage ransom payment. Recovery from an encryption event is great and all, but it doesn’t solve the problem of your new regulatory fine and legal…

Isn't that basically the author's point?

> This brings me back to my original point: Nobody (i.e., business leaders) cares about security. What they care about is avoiding lost revenue due to application downtime, extortion, and lawsuits.

Followed by arguing that fines and reputation loss, under the current status quo, aren't seen by business leaders as being extraordinarily disastrous.

Re: Nobody Cares About Security

#4
The author ain't wrong - security has a massive usability issue, and a lot of legacy security vendors don't seem to care about understanding the UX or workflows of various different personas.

The newer generation of companies and startups are better, but it's still a work in progress.

Re: Nobody Cares About Security

#6

Disagree. Security isn’t just about recovery. Say you get breached. Many threat actors are well aware of global privacy laws and exfiltrate data and threaten to release it if not paid the ransom. Some go a step further to notify privacy regulators of the breach to further leverage ransom payment. Recovery from an encryption event is great and all, but it doesn’t solve the problem of your new regulatory fine and legal…

Isn't that basically the author's point? > This brings me back to my original point: Nobody (i.e., business leaders) cares about security. What they care about is avoiding lost revenue due to application downtime, extortion, and lawsuits. Followed by arguing that fines and reputation loss, under the current status quo, aren't seen by business leaders as being extraordinarily disastrous.

> What they care about is avoiding lost revenue due to application downtime, extortion, and lawsuits.

This is starting to align with security needs now too (eg. ransomware, data breaches, etc).

Re: Nobody Cares About Security

#7

The author ain't wrong - security has a massive usability issue, and a lot of legacy security vendors don't seem to care about understanding the UX or workflows of various different personas. The newer generation of companies and startups are better, but it's still a work in progress.

Many aren't better just fancier.

Re: Nobody Cares About Security

#8
post #5

Surprisingly few companies (or people) care about paying for good security.

Security is hard, and determining what is worth paying for when it comes to security is arguably even harder - there seem to be a higher than typical amount of snake oil salesmen and grifters in the industry.

Re: Nobody Cares About Security

#10
post #5

Surprisingly few companies (or people) care about paying for good security.

The problem with paying for good security is that it's very difficult for non-security experts to evaluate the genuinely effective ways to do that.

Is buying antivirus "paying for good security"? Hiring the first security firm that showed up in a Google search?

If you advertise for a security person to join your company, how do you effectively interview candidates?

Post reply on HN