Live data from Hacker News

The Colossal, Monumental Screw Up That Is Marriott Security

danmunro.com

31–38 of 38 posts

Re: The Colossal, Monumental Screw Up That Is Marriott Security

#31

The way this article talks about IDS sounds, to me, like someone who has never worked with IDS professionally or on any large scale. This goes for other points in the article as well, but that seemed particularly glaring. I don't intend to defend Marriot, from other coverage it sounds like someone did a very poor job (although not necessarily Marriot itself). But this article also makes things sound far simpler than…

Agreed. My first thought was "'Any IDS worth its weight in salt'? That creature doesn't exist, my friend."

Re: The Colossal, Monumental Screw Up That Is Marriott Security

#33

Disclaimer: Not defending Marriott, as their Starwood Rewards/Marriott Rewards merger has been demonstrably one of the most epic, public IT integration failures that I've ever personally witnessed as a consumer bystander. BLUF: I am a huge advocate of companies being fined on the basis of number of people affected and types of data leaked. This incentive to not be fined will be built into the formal or informal risk…

I'm interested in a proposed value/penalty for individual and combinations of data. Even if it's a paper napkin approach.

Full name, probably not worth even a penny? Full name plus address plus phone? $0.05? Passport number alone? I have no idea, maybe zero, but full name + address + phone + passport + social? Could that be worth a $2 per instance for a fine?

What about direct compensation for the person whose information is leaked? I've read recommendations people should get new passports because such information can be used to track people's movements across borders https://i94.cbp.dhs.gov/I94/#/history-search

So what if the per instance is really worth $110 (base value to replace the passport)? If 100 million people are affected, that's $11 billion. Not including fine. The Starwood acquisition was $13 billion.

In other words, it could nearly bankrupt the company, if it weren't for the success companies (and markets too, really) have had at shifting the burden of breaches away from the company, an effectively freeloading.

Re: The Colossal, Monumental Screw Up That Is Marriott Security

#34

The way this article talks about IDS sounds, to me, like someone who has never worked with IDS professionally or on any large scale. This goes for other points in the article as well, but that seemed particularly glaring. I don't intend to defend Marriot, from other coverage it sounds like someone did a very poor job (although not necessarily Marriot itself). But this article also makes things sound far simpler than…

> The retrieval of a large file would be a good opportunity for detection by SIEM content, but without further knowledge of the application it might not be - large file transfers from that machine might be normal as part of e.g. batch processing.

Or an eccentric and occult edge case like "backups", especially if it's a database system. Sorry for the snark, but I've had to tell some people the importance of backups for production persistence like a broken record for a week or two.

And sure, you could have IDS rules / firewalls setup to flag or block traffic except to the backup storage hosts and the replication servers and the batch processing servers and the monitoring andso on and so on, flag files, ...

But that stuff is hard, requires a lot of maintenance and adds risk to a lot of critical / stress-powered processes. Change your backup storage at 3 am due to hardware failures? Whoops, the firewall of database host #13 wasn't updated, and now you have no more backups from that host.

Re: The Colossal, Monumental Screw Up That Is Marriott Security

#35

I'm an Information Security and Privacy professional, and until there are real penalties for a lack of security nothing will change. Go see the Ford Pinto case, cheaper to pay lawsuits from deaths than fix the problem, then don't fix the problem. The other problem is an utter and total lack of technical knowledge by Sr. Management, they hire charming idiots who tell Sr. Management what they want to hear. I've been to…

The appearance of security is much more important than actual security. I would gander that is precisely because there is no real penalty outside of anything that would be considered the cost of doing business.

How to enforce punitive action upon a company with such international reach is the real question.

Re: The Colossal, Monumental Screw Up That Is Marriott Security

#36
OP here, thanks everyone for the interest and discussion in the topic. Awareness and open discussion is going to be the disinfectant our industry needs to improve security hygiene. I have only recently taken blogging seriously and am still working to find my voice and balance between too little information and information overload. I took the feedback here to heart and tried to improve and clarify my ideas and recommendations. Sorry if there's still not much specific information provided, I wanted to keep it at a high level, maybe that was not the best call -- anyway the feedback is very helpful.

Re: The Colossal, Monumental Screw Up That Is Marriott Security

#37
post #2

Pays to read the original article, it wasn't Marriott it was the company they bought, long before the purchase. Marriott's system was not compromised.

I wonder how much IT security will start to play into due diligence efforts in acquisitions in the future. It seems there's an inordinate amount of risk exposure in security matters. Then again, I think Equifax is still a healthy company financially, so maybe not.

Re: The Colossal, Monumental Screw Up That Is Marriott Security

#38
post #11

What's "M & M Security"? Linked article never defines the "M"s, I had no luck googling.

It's linked, and it's perimeter based security. I've also known it as egg-based security - once the shell breaks, you've got a big mess on your hands.

Ah, I get it now, thanks. Yes, it was linked, but the linked article didn't explain the metaphor either. I wasn't thinking of the candy, now I get it.
Post reply on HN