Live data from Hacker News

U.S. Senate to probe whether legislation needed to combat cyber attacks

reuters.com

11–20 of 66 posts

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#12

It's mind boggling that the government needs to require this. What bureaucrat is refusing some IT person from requesting the funds doing this?

Literally all of them. Security is a cost center, and non bureaucrats salaries are minimized as much as possible until you are left with "warm body to fill chair". Even the NSA doesn't pay well, compared to private sector.

> Even the NSA doesn't pay well, compared to private sector.

On the other hand, I bet it's pretty fun working for the NSA: https://en.wikipedia.org/wiki/NOBUS

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#13

Earlier quoted context omitted.

Literally all of them. Security is a cost center, and non bureaucrats salaries are minimized as much as possible until you are left with "warm body to fill chair". Even the NSA doesn't pay well, compared to private sector.

I'm wholly aware the private sector pays better, but in the grand scheme of pay/average citizen, they still make decent salaries. In that regard, why is upper management ignoring IT security at a base-line level of at least rotating backups? Like even that is pretty cheap and you can revert systems back within a day or two with a few days of lost work. Nobody is saying have a top tier security team.

I was on a temporary pentesting contract at a Fortune 500 company, and the reason for ignoring security came down to cost. Our contact in their IT department said that when they were trying to get the budget to fix their longstanding security issues, they were told that it's cheaper to accept occasionally getting hacked than it is to fix things. They said that public relations people at big companies had pushed the "the bad guys attacked us, it could have happened to anyone" narrative so well that besides a few day dip in stock prices, there would be no negative financial impact on the company. The average person thinks of getting hacked like being robbed at gunpoint, where it can happen to anyone through no fault of their own.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#15

I am always worried non-programmers don't sufficiently understand how pathetic it is that we limp along with bloated Unix and other accidents of history that were never retired. And this lassies-fair approach to cleanliness and reducing complexity both makes us more vulnerable and less productive.

Why single out Unix and not, you know, Windows ?

Exactly -- Windows is the biggest vector for malware, by orders of magnitude.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#17

Legislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.

NSA’s posture has been both for at least twenty years. They have separate divisions and everything.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#19
post #13

Earlier quoted context omitted.

I'm wholly aware the private sector pays better, but in the grand scheme of pay/average citizen, they still make decent salaries. In that regard, why is upper management ignoring IT security at a base-line level of at least rotating backups? Like even that is pretty cheap and you can revert systems back within a day or two with a few days of lost work. Nobody is saying have a top tier security team.

I was on a temporary pentesting contract at a Fortune 500 company, and the reason for ignoring security came down to cost. Our contact in their IT department said that when they were trying to get the budget to fix their longstanding security issues, they were told that it's cheaper to accept occasionally getting hacked than it is to fix things. They said that public relations people at big companies had pushed the "…

In terms of dollars and cents that makes complete sense.

Real security is extraordinarily expensive. Very rarely is that compatible with shareholder value.

Post reply on HN