I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
I generally agree with the main thrust of your argument, but this seems way over the top. I don't know if every brick and mortar business in the world can afford to hire a dedicated security engineer. Should they all just close shop? And if we're going by Wikipedia's definition of PII, probably at least 50% of the websites in the world. Including this one. Maybe you don't mean all that, but if I am to take what you p…
Insanely irrational? If you are comfortable handing your information to companies who do nothing more than the bare minimum to make sure it's safe, that's insanely irrational. I get tired of companies giving my information away. I really do. There's no excuse for it.
Security is by no means a solved problem, nor is it possible to solve at this point. But how often do you hear that the company wasn't hashing, wasn't encrypting, wasn't paying attention to their security tools? Damn near every time. Things like this very, very rarely happen to companies who take security seriously.