The way this article talks about IDS sounds, to me, like someone who has never worked with IDS professionally or on any large scale. This goes for other points in the article as well, but that seemed particularly glaring. I don't intend to defend Marriot, from other coverage it sounds like someone did a very poor job (although not necessarily Marriot itself). But this article also makes things sound far simpler than…
The Colossal, Monumental Screw Up That Is Marriott Security
31–38 of 38 posts
Re: The Colossal, Monumental Screw Up That Is Marriott Security
#32Re: The Colossal, Monumental Screw Up That Is Marriott Security
#33Disclaimer: Not defending Marriott, as their Starwood Rewards/Marriott Rewards merger has been demonstrably one of the most epic, public IT integration failures that I've ever personally witnessed as a consumer bystander. BLUF: I am a huge advocate of companies being fined on the basis of number of people affected and types of data leaked. This incentive to not be fined will be built into the formal or informal risk…
Full name, probably not worth even a penny? Full name plus address plus phone? $0.05? Passport number alone? I have no idea, maybe zero, but full name + address + phone + passport + social? Could that be worth a $2 per instance for a fine?
What about direct compensation for the person whose information is leaked? I've read recommendations people should get new passports because such information can be used to track people's movements across borders https://i94.cbp.dhs.gov/I94/#/history-search
So what if the per instance is really worth $110 (base value to replace the passport)? If 100 million people are affected, that's $11 billion. Not including fine. The Starwood acquisition was $13 billion.
In other words, it could nearly bankrupt the company, if it weren't for the success companies (and markets too, really) have had at shifting the burden of breaches away from the company, an effectively freeloading.
Re: The Colossal, Monumental Screw Up That Is Marriott Security
#34The way this article talks about IDS sounds, to me, like someone who has never worked with IDS professionally or on any large scale. This goes for other points in the article as well, but that seemed particularly glaring. I don't intend to defend Marriot, from other coverage it sounds like someone did a very poor job (although not necessarily Marriot itself). But this article also makes things sound far simpler than…
Or an eccentric and occult edge case like "backups", especially if it's a database system. Sorry for the snark, but I've had to tell some people the importance of backups for production persistence like a broken record for a week or two.
And sure, you could have IDS rules / firewalls setup to flag or block traffic except to the backup storage hosts and the replication servers and the batch processing servers and the monitoring andso on and so on, flag files, ...
But that stuff is hard, requires a lot of maintenance and adds risk to a lot of critical / stress-powered processes. Change your backup storage at 3 am due to hardware failures? Whoops, the firewall of database host #13 wasn't updated, and now you have no more backups from that host.
Re: The Colossal, Monumental Screw Up That Is Marriott Security
#35I'm an Information Security and Privacy professional, and until there are real penalties for a lack of security nothing will change. Go see the Ford Pinto case, cheaper to pay lawsuits from deaths than fix the problem, then don't fix the problem. The other problem is an utter and total lack of technical knowledge by Sr. Management, they hire charming idiots who tell Sr. Management what they want to hear. I've been to…
How to enforce punitive action upon a company with such international reach is the real question.
Re: The Colossal, Monumental Screw Up That Is Marriott Security
#36Re: The Colossal, Monumental Screw Up That Is Marriott Security
#37Pays to read the original article, it wasn't Marriott it was the company they bought, long before the purchase. Marriott's system was not compromised.
Re: The Colossal, Monumental Screw Up That Is Marriott Security
#38What's "M & M Security"? Linked article never defines the "M"s, I had no luck googling.
It's linked, and it's perimeter based security. I've also known it as egg-based security - once the shell breaks, you've got a big mess on your hands.