Comment by jonplackett

2 days ago

We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible.

‘Just make the encryption secure and so we can read it’

‘Just check everyone’s id but make it totally secure’

They do not care about 'secure' part at all.

  • This is the answer. The more failures, the more justification for more draconian restrictions of civil liberties.

    I can hear the defense now: "Oh, yeah, you blame the honest, good, handsome people trying their best to protect you and you let the hackers off scot-free! We must make sure that hackers don't have access to the tools that aid them to commit these crimes, like books and computers. Anyone could be a hacker."

    • It already works like that. "Identity theft" is entirely framed as a problem for the citizen, affecting them and that it's their responsibility to resolve or face the consequences (credit score, collections, etc.) when all the citizen did "wrong" was choose an institution who cared more about profit than security. For the institution, all their obligation often seems to be is to "partner"[1] with a credit monitoring service.

      [1] A credit monitoring service that will give the institution that "free 12 months" at a vastly reduced bulk rate because it knows that in order to sign up for free credit monitoring you actually sign up, with a card, for their top tier product (which might otherwise be $50+ a month) on what is effectively a 12 month trial after which they switch you over to a paid subscription (hell, there may even be commissions paid to the institution for anyone who neglects to cancel quickly enough). The incentives are so perverse.

That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain.

The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know.

I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?

  • As Ops person, massive doubt. I've been at companies that have gotten hacked twice now, neither my department though. Both times, security vulnerabilities that hackers got into were well known, the tickets were in the backlog and deprioritized over feature requests.

    I've also seen cases where it's like, maybe we shouldn't share S3 Root Creds or put it on the VPC so we can monitor outgoing traffic but too many applications would need to be redeployed for that so skip it. Those 2 year old tickets were still sitting in the backlog when I left.

    If we ever get report, it's extremely likely going to be massive failure and only way to change this is fines for company that are bankrupting.

    EDIT: Oh yea, SOC2 needs to go away. It's security theater that's just giving cover to companies.

  • I'd say it's not so much "as secure as we know how" and a lot more "as secure as we're willing to pay for". I'm sure this company has competent sysadmins and devs who'd be happy to lock things down. Usually management doesn't want the expense or the hassle.

  • This is kinda my point though - just don’t do it in the first place is the answer. Nothing is unhackable. So don’t create a massive honeypot in the first place.

  • Those aren’t the people in charge. People like 93 year old Senator Chuck Grassley are calling the shots.