Live data from Hacker News

Learning from a Year of Security Breaches

medium.com

51–53 of 53 posts

Re: Learning from a Year of Security Breaches

#51
Logging everything is a great idea, but only if you read the log data. Target installed a system to monitor for certain kinds of security hacks which wrote to their logs files. The logging was turned off due to a high number of warnings cluttering up the logs. Of course the logging was telling them they were being hacked which they ignored for months, leading to all sorts of business disasters.

Re: Learning from a Year of Security Breaches

#52

Earlier quoted context omitted.

Can only speak about my corner of a very large organisation; - Technical debt of custom coded solutions is a known issue across our organisation. New strategy is to move to market solutions, therefore outsourcing the risk to organisations with (hopefully) better code management than we have. For my corner, we don't have technical debt measured accurately enough for my liking. - Yes, we pay for an use centralised logg…

> (hopefully) I hope you are auditing the code of those external orgs.

Part of the goal is to establish an arms length relationship to lower legal liability.

Re: Learning from a Year of Security Breaches

#53
Great article! For those interested in security debt and how it relates to startups, I wrote this in 2011: https://www.veracode.com/blog/2011/02/application-security-d... and presented it that year: https://www.youtube.com/watch?v=MKdiiXgvz_U This predates by a year the referenced security debt presentation which has much of the same material uncited.
Post reply on HN