Let's Stop Giving Retailers a Free Pass on Data Breaches
bloomberg.com
bloomberg.com
* The OPM breach: https://www.opm.gov/cybersecurity/cybersecurity-incidents
* Equifax: https://www.consumer.ftc.gov/blog/2017/09/equifax-data-breac...
In both cases the amount of data leaked per person is huge, way more than just an email address or credit card number. And in both cases there was no way for customers to opt out of their data being gathered. Those two characteristics seem related. The most valuable data isn't going to be somewhere that is subject to regulations like GDPR. And it's going to be running on the same insecure stacks and practices as everything else we see. If we want to plug holes, these are the sorts of places where we need to begin. Facebook is a child's bagatelle in comparison. MyFitnessPal doesn't even register.
Though it's unfair calling the OPM incident a "breach" as management of the database was outsourced to an outsourcer to an outsourcer so the final party had full read/write access over it for potentially years. As I noted at the time, every clearance granted or denied during that period must be reviewed.[0]
0 - http://caseysoftware.com/blog/opm-background-check-hack-a-di... (I had a clearance previously so I was included in this one.)
But losing credit card numbers is merely an inconvenience. CC users aren't even liable. On the other hand, losing your SSN and other supporting details can be devestating.
Corporate media has been giving passes with one-off coverage that often neglects to mention any proposals for remedying long-term public ramifications. But the public's interest isn't well served by corporate media nor is public interest properly evaluated by corporate media.
Let's also stop thinking the stock market is a proper means of evaluating something applicable to most people's interests, because that's never been true. The stock market has more to do with wealthy people than most people.
The corporate death penalty seems right and proper for very egregious offenses like credit rating agencies because the public will suffer the most and for the longest time (possibly the rest of their lives) when these records are insecure. Organizations will continue to lazily make evaluations based on these records but the records could have been tampered with. And judging by Equifax's successful lobbying, the ratings agencies get away with scarce punishment and therefore have little reason to care about fixing what they broke. Relatedly, it's time we stopped trusting so few organizations with something so precious. The market just isn't designed to handle truly important things, so we should stop trusting it to do so.
No, let's not give them or any other organization passes, but let's also realize that most of these organizations use proprietary software (untrustworthy by default) to keep that data secure where nobody (including the organization) simply can't do effective audits. How proprietary software works is a secret, so such software is structurally incapable of ever being reasonably considered a sound choice for data safety. And organization's choices affect user's data safety, so users have an interest in this but not enough control over how their data is stored.
This is completely incorrect. The only example of a data breach you gave was a result of open source software (Apache Struts for Equifax). Open source software has contributed to plenty of data breaches, and I seriously doubt you've ever audited the millions of open source packages and dependencies you're using.
This is bad corporate security, by believing this type of nonsense. Then you'd inadequately assign risk, and fail to protect against real threats, instead focusing on 1990's "M$" risk.
> How proprietary software works is a secret
I don't need to know how exactly software works to make calculated decisions about risk. We sign vendor service agreements with other companies, that give us assurances about their data handling practices, their audit/compliance history, etc. I can look at how vendors manage their PSA process, how transparent they are with security disclosures, things like that.
These executives get paid a large sum of money, and then skirt all responsibility when these things happen. They get fired and move onto the next gig like nothing ever happened. There is no accountability for these failings.
In Ancient Rome the builder/designer of an arch was required to stand under it as the wooden scaffolding was removed (the most dangerous time).
It is high time we re-introduced accountability into our governance systems.
We have a set of standards that define what negligence looks like for data breaches, security, etc. If a company is found to not adhere to these standards they would be found negligent and assessed some financial penalty.
If a company is found to be adhering to the standards, and is hit by a 0-day, the financial penalty would be negligible or 0.
Some standards like PCI attempt to do this, but to date they have no real teeth. GDPR may be the change we need.
I have deep concern that C-levels will learn that breaches don’t matter, just have a CISO you can behead and replace when it does.
Yes, I agree completely, that C-levels will see that the CISO is a replaceable widget that is nothing more than a scapegoat.
I don't know how you define "deliberately doing something wrong" without either making it too broad or worthless.
It's rare that any organization "deliberately" exposes their customer information. It's also effectively impossible for any organization to guarantee that the data is unbreachable.
It's perfectly possible to have a data breach and not get fined, and as long as you didn't do anything too careless that would allow a breach to happen you're probably in the clear.
Everyone knows there's no perfect system.. but in regards to what we're talking about it's much better to have personal data be a liability rather than an asset, because it puts incentive on companies to only use what they need and make efforts to protect it appropriately.
What if I'm just unaware of the standard or incompetent?
Not all programmer who save password in plaintext starts by thinking "I'm going to intentionally doing this wrong so that it breaks all security guidelines".
Who determines how much careless is "too" careless? "slightly careless" but with huge consequences is more concerning than "incredibly careless" but with no consequences.
Really the punishment should be matching the value of the breach. For example with HIPAA breaches, you can get fined $10k or so, PER RECORD -- obviously medical data is exceptionally more sensitive than most. Credit data should be covered under a HIPAA-like statute. Under HIPAA there's no such thing as "a little careless" -- you either f'ed up or you didn't. There's no gray area.
Lets not pretend we will get a perfect law the first time around. Closing a few gaps is already a good first effort. We just need to be willing to close a few more as we discover them. Note too that there are always unintended consequences - we also need to be quick for calling for the elimination of a well intended law where the unintended result is a negative, even if it does get some bad actors.
It never transmits your card number or name to the retailer. Instead it uses a token (substitute number) that is tied to iPhone-based authentication. Even if stolen, it's useless.
So I don't think we should give retailers a pass, but the bigger issue here is the whole PCI compliance architecture was a security nightmare to begin with. We should usher in modern methods like Apple and Samsung Pay ASAP that remove that retailer vulnerability altogether.
It's amazing the effect a CEO locked in a cage for a few years like an animal has on the population of CEOs as a whole. Treat digital infrastructure like we treat real infrastructure. If people built bridges the way we build software infrastructure, rafts of executives would be rotting in prison.
Never going to happen. Especially in the current 'business friendly' administration. This [1] book does a great job at explaining why. I don't think we'll see a CEO behind bars for anything white-collar in our generation. Sadly. Judges and prosecutors are political animals too, you know.
[1] https://www.amazon.com/Chickenshit-Club-Department-Prosecute...
I've known a few CEOs (not personally) and not one of them was in charge of anyone who had these types of responsibilities, directly or indirectly.
Plenty of C-level and director types have large paychecks. To randomly place blame because of that would only make matters worse. Those responsible would have a convenient scapegoat, and CEOs would just demand higher salaries as compensation for taking on risks outside of their control.
Honestly, the whole "get the CEO" movement has always smacked of intellectual dishonesty to me, as though catharsis were in any way a decent value to base public policy on.
https://www.educationdive.com/news/cost-of-education-data-br...
HomeDepot: https://www.bankinfosecurity.com/court-clears-way-for-banks-...
Target: https://consumerist.com/2017/02/03/court-to-review-targets-1...
This is going to be the long term "no free pass" effect of such neglect. Or, if we actually have a "marketplace" with consumer choice, it will be. People will avoid the threat and hassle, and show elsewhere.
Only so far, the larger retailers -- and their incompetent management -- seem to be getting away with their neglect.
P.S. I'm not arguing against better regulation and effective penalties. Rather, I guess, while pointing out the "risk" of poorly serving the market, I'm saying that it doesn't really seem to be working, so far.
If you can't keep data secure you don't need to be in business.
http://projects.thestar.com/temp-employment-agencies/
I completely agree with you. Shit security should cost money. I just think it has to be something like data leak liability insurance. The costs of having shitty security would be reflected in higher insurance premiums. That way, financial math would be firmly on the side of keeping data secure, instead of limiting exposure via corporate shell games.
Of course whoever backs the bond doens't want to pay, so they will do due diligence in relation to the value of the bond.
All this talk of "breaches" is a disingenuous framing to deflect from the root of the problem, similar to that continually-pushed nonsense of "identity theft". As if all the surveillance in the world is completely acceptable, just as long as some vague weird other doesn't gain access to that same capability!
Equifax shouldn't be put out of business for having leaked their trove, but for having collected all that surveillance data in the first place.