← Back to context

Comment by itake

2 days ago

"Move fast and break things"

I could spend an extra 5 minutes doing it "right" or I can get what I need done and have a 0.001% chance of there ever being a problem (since there are other security measure in place, like firewalls, api key rotation, etc.)

Even when security gaps are exploited, the fallout tends to be minimal. Companies that had their entire database of very sensitive information leaked are still growing users and at worst paid a tiny fine.

> Companies that had their entire database of very sensitive information leaked are still growing users and at worst paid a tiny fine.

Or end up bankrupt with criminal charges for CEO: https://yle.fi/a/74-20027665

  • Bankrupt? I didn't read about any financial penalties in that article. The board fired him back in 2020 when they found out, and then he blamed 2 IT people. Instead, he got 3 months suspended sentence (in a Finnish jail, which is not exactly like a US jail). The company still exists btw.

    • It got bankrupt in 2021 in an aftermath of the breach. I think they sold some of their operations forward before that.

      The actual breach wasn’t that advanced hacking. They had copied their production data with all the patient information to test database which was publicly available and had default credentials.