Live data from Hacker News

Nobody Cares About Security

adatosystems.com

61–70 of 93 posts

Re: Nobody Cares About Security

#61

I've been saying this since at least 2009 when the company I worked for was sending credit card info from card readers across the network in plain text and they dragged their feet to fix it even though they knew we were violating some serious SOX policies. At another company in 2015, I discovered we were sending user credentials for a large hospitals in plain text across the network and need to fix this ASAP. When I…

I have a feeling that we've developed an economy that's too focused on short term goals and this prevents us from making more success. Short term goals matter, but not at the cost of long term.

I think these are the main problems and why it's hard to tackle. I think they can help prevent issues but I'd like to hear other suggestions:

1) You can't measure maintenance or security benefits the same way as you can measure costs of failures. You can measure the cost it takes to implement, but when you do you can't measure the counterfactual cost of if you hadn't. It's not actualized. But I'm confident maintenance is always cheaper than repairs. Don't fix things that aren't broken, but do fix things before they break. We need to learn the difference.

2) the world is complex and many costs are outsourced and distributed. I like to think of this like the inverse software success. Software is great because once made you can copy it trivialy and distribute it. But the down side is the mistakes propagate too! So something that may only cause a second delay is seen as miniscule but it's not when you consider a hundred million users using it every day. Enshitification is about these little things adding up and accumulating.

3) we avoid slack like the plague. I don't mean slacking off, but slack in the system. You don't make a ship and only have enough lifeboats for exactly the number of passengers. You need more because you can't assume everyone perfectly makes it to the right life boat, especially in an emergency. Covid should have been a real wakeup call but the global economy shouldn't shut down anytime a single ship gets stuck.

4) doing good and quality work has the stability of an inverse pendulum. Most evil and shit isn't caused by malice, it's that it's harder to do good and with longer and more complex tasks it's easier for something to go wrong along the way which then snowballs.

So a big belief I have is trust we need to slow down if we want to speed up. Move fast and best things is great when problem solving but you need to also also go back and clean up all the mess you've left behind. We've become so accustomed to technical debt we aren't even recognizing how much we have.

We can't be just focused on the next quarter. We're in a much more complex world. Even early humans had to plan for winter. I know what I'm asking for is difficult but nothing worth doing is usually easy. All of us have done hard things and continue to do hard things. But importantly, try not to distribute and amplify mistakes. Squash them when they're small. Don't ask for permission, just fix things.

Re: Nobody Cares About Security

#62
post #10

Earlier quoted context omitted.

The problem with paying for good security is that it's very difficult for non-security experts to evaluate the genuinely effective ways to do that. Is buying antivirus "paying for good security"? Hiring the first security firm that showed up in a Google search? If you advertise for a security person to join your company, how do you effectively interview candidates?

No F500 tier executive is doing that. They paid Accenture and Gartner to tell them what to do. Ditto for having them set up a security organization -- get Accenture to sit a temporary CISO, hire some people, and then fuck off. Hopefully the replacements work! Mom and Pop shops might use Google, but in 2024 they're usually using whatever the local, oversubscribed MSP is selling.

and the problem there (as I see it) is that they don't care about security, they care about passing their audit.

"Passing our audit" has been presented with measurable consequences (cannot sell to customers) and finite, well-defined actions (this is what the audit list looks like).

What I'd like (the goal of the follow up article, coming soon) is to present the value of security in a way that makes the justification of the effort viable and palatable.

Re: Nobody Cares About Security

#63

Software security is the absence of vulnerabilities, which is a special case of the absence of bugs. People are not interested in security because they are not interested in quality. Even those environments that are supposed to be high security, are in fact buggy, slow and very frustrating to use - revealing that they are almost certainly riddled with vulnerabilities as well. It's implausible that a system could be s…

You are talking about security through correctness, which is indeed not achievable. However it's not the only approach to security [0]. Security by isolation really works according to the statistics [1].

[0] https://blog.invisiblethings.org/2008/09/02/three-approaches...

[1] https://www.qubes-os.org/security/xsa/

Re: Nobody Cares About Security

#64

I've been saying this since at least 2009 when the company I worked for was sending credit card info from card readers across the network in plain text and they dragged their feet to fix it even though they knew we were violating some serious SOX policies. At another company in 2015, I discovered we were sending user credentials for a large hospitals in plain text across the network and need to fix this ASAP. When I…

I'd argue that at least some of the problem is that we are forced to record fundamentally insecure data.

If we could replace things like SSNs, passport numbers, credit card numbers, etc. with org-specific tokens/certificates, they'd be largely useless to anyone else.

Sadly, no one cares enough about security to fix the problem though, not even governments.

Re: Nobody Cares About Security

#65

There are many common software tasks that are just hard to do securely, and there is an incentive to keep it that way. Security is a huge industry mostly filled with people who check boxes and memorize obscure trivia. Consider TLS, the "industry standard" for connecting two processes securely over the network. There is a huge amount of complexity just to accomplish something that should be secure by default. Certific…

Security should not be box checking. Security is seeing your cyber domain as territory you are militarily holding from the enemy. Security is understanding you're in a game of cyber spy vs spy with a globe of adversaries working to 'get' you. You can't checkbox this, it takes fluid, dynamic, multi-step thinking. In security, you are at constant war. It's not like being a Rent-A-Cop™ at the mall or bank, who is mainly a box checking scarecrow. Security is srs bidness.

Re: Nobody Cares About Security

#66
post #53

Earlier quoted context omitted.

Until they are fined 10% of yearly revenue. That's why you need a strong government.

An alternate, market-based solution would be insurance companies who impose requirements for insurance. That increases the chances of finding an economic balance between security and productivity. A government regulation applies to everyone, even if it no longer makes sense: an insurance company whose requirements are out-dated will be out-competed by others, while an insurance company whose requirements are insuffic…

> An alternate, market-based solution would be insurance companies who impose requirements for insurance.

This is exactly why the CrowdStrike disaster happened: https://news.ycombinator.com/item?id=41011065

Re: Nobody Cares About Security

#67
post #53

Earlier quoted context omitted.

Until they are fined 10% of yearly revenue. That's why you need a strong government.

An alternate, market-based solution would be insurance companies who impose requirements for insurance. That increases the chances of finding an economic balance between security and productivity. A government regulation applies to everyone, even if it no longer makes sense: an insurance company whose requirements are out-dated will be out-competed by others, while an insurance company whose requirements are insuffic…

The market for cybersecurity insurance is collapsing:

https://www.theinformation.com/articles/companies-are-ditchi...

but the OP's arguments also apply to insurance, yet businesses buy insurance every day. The difference is the fines and liability for data breaches are so paltry it is the rational thing to do not to invest in security. This can only change through legislative action. I wouldn't hold my breath.

Re: Nobody Cares About Security

#68

The author ain't wrong - security has a massive usability issue, and a lot of legacy security vendors don't seem to care about understanding the UX or workflows of various different personas. The newer generation of companies and startups are better, but it's still a work in progress.

If you choose "security vendor", you have been scammed already. This is the whole issue: you have to work (cleverly), not just pay for it.

Re: Nobody Cares About Security

#69

I've been saying this since at least 2009 when the company I worked for was sending credit card info from card readers across the network in plain text and they dragged their feet to fix it even though they knew we were violating some serious SOX policies. At another company in 2015, I discovered we were sending user credentials for a large hospitals in plain text across the network and need to fix this ASAP. When I…

I'd argue that at least some of the problem is that we are forced to record fundamentally insecure data. If we could replace things like SSNs, passport numbers, credit card numbers, etc. with org-specific tokens/certificates, they'd be largely useless to anyone else. Sadly, no one cares enough about security to fix the problem though, not even governments.

We are replacing such things, although USA is a decade or so behind the rest of the world due to various legitimate sociopolitical and historical reasons.

In most places worldwide identifiers equivalent to SSNs and passport numbers aren't really treated as financial secrets; they may not be totally public due to certain privacy aspects, but they generally don't result in financial identity theft, that's a fixable problem of certain regions (like USA and a few others). Similarly, moving to proper credit card authentication (chip&pin or wireless chip when card is present, 3dsecure when not, etc) has made many credit card numbers mostly useless for thieves unless accompanied by a more serious compromise.

But all these things above have been implemented only because (and where, and when) the actual companies became financially liable for the consequences - as long as the losses/fraud/etc hit only the users/consumers, there is no motivation to fix anything. Shift the liability to the company which accepts that fundamentally insecure data as good enough, and they'll figure out some way to implement a secure process.

Re: Nobody Cares About Security

#70

> The problem with security is that it’s impossible to measure your ROI Sometimes I wonder what we lost by only working on things with measurable impact

There's an actual name for this fallacy: https://en.wikipedia.org/wiki/McNamara_fallacy

> The McNamara fallacy (also known as the quantitative fallacy),[1] named for Robert McNamara, the US Secretary of Defense from 1961 to 1968, involves making a decision based solely on quantitative observations (or metrics) and ignoring all others.

Which had a profound effect on the Vietnam War

I agree, by the way, we shouldn't focus only on measurable metrics. Humans, and businesses should also value "norms and values". Although I have no idea how to evangelise this

Post reply on HN