Should we be focusing our efforts more on how to make "identity theft" (i.e. fraud) more difficult, even when someone knows all your data?
Something more tied to your physical self, whether 2FA or something else?
Should we be focusing our efforts more on how to make "identity theft" (i.e. fraud) more difficult, even when someone knows all your data?
Something more tied to your physical self, whether 2FA or something else?
I disagree. I’d take the Economists route, which is looking for the incentives that drive motivation. If companies were held to a higher standard of accountability, imagine how many would beef up their security. For decades, security researchers have been poking fun at how ridiculous some of these sites are at handling security, and nothing ever happens.
Now, imagine if there was severe economic accountability to a company that was hacked. Perhaps payouts to each person affected (in this case, to all 150m). I imagine you’d see security become a top priority very quickly at most companies.
[0] https://www.bleepingcomputer.com/news/security/first-gdpr-sa...
The Flirty chat app is fined for leaking 808,000 emails to the tune of 20,000 EUR.
[1] https://news.ycombinator.com/item?id=18531588
The Cuddly chat app is fined for using plaintext password storage to the tune of 20,000 EUR. (No hack known as of yet?)
[2] http://fortune.com/2018/11/27/uber-eu-data-hack-fines/
As foreword, this occurred under older privacy laws and not quite GDPR. Many sources agree that GDPR would increase fine sizes in a repeat event.
Due to a data breach at Uber exposing 57 million people's records, they were fined 600,000 EUR by the Netherlands and 385,000 GBP by the UK.
[3] See nkkollaw's comment below/above.
1: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
Uber is somewhere around $10b gross revenue, so $400m fine for every breach. Sure it's "just a cost of doing business". It also means that it's better to spend $200m beefing up their security to reduce from 1 data breach every year to one every 5 years.
Marriot revenue is $23b, so that's a potential $920m fine.
IHG (say), who invest in security and don't have a breach, get to charge less for their hotels, or make more profit.
Much more than "just a cost of doing business" for the majority of companies.
If I kill somebody, that person isn't there anymore, you don't think deterring other from killing other people isn't reasonable?
While companies could probably do better than they are right now, hacks like this are probably never going to be eliminated. There are too many companies and too many developers for nobody to make mistakes, even when they're being mindful not to. Investing in solutions that assume hacks will happen seems reasonable to me.
I really wish more developers had at least a basic ethical grounding and didn't just go "fuckit, revenue!". (Or, in larger companies, "fuckit, my boss told me")
And when you consider opportunity cost - even just double-checking you aren't affected takes a minute of time, as a consumer, that means this hack just wasted close to a thousand years of human life.
Where's the accounting for the opportunity cost of that?
In other words, this is an irrelevant nit that serves no purpose except derailment.
If basic ethical grounding requires security to be the top priority, and security work is inexhaustible, then it must be unethical to ever work on the product being secured.
If basic ethical grounding requires safety to be the top priority, and safety work is inexhaustible, then it must be unethical to ever work on the product being safe.
An ethical approach requires you to reason about which actions are moral, not to be "done" with something. As I said, even a basic knowledge would be really helpful.
If you don't store valuable data, you won't have large premiums.
If your business model requires storing such data, you better have the revenue to pay the premiums.
The situation is identical to you wanting to have an untamed lion in your back yard. Provided you have the right security in place to ensure it can't hurt me, your neighbor, then the litter box is your problem. If however you do not have the right protections in place, then I have every right to ensure the lion is removed from the neighborhood.
I'm not saying we can be invulnerable but we need to raise the lowest common denominator so that it's not a walk in the park to steal millions of records. You just need the weakest link to make everyone vulnerable but I do think positive collective behavior can counter that -- especially when you make it easy with things like Let's Encrypt.
I dont think you have quite thought it through. Do you honestly want to have to do code audit on all libraries you use? Freeze all versions? Have a chain of signoffs for every change?
I have briefly done consulting in a place like that -- developers were absolutely miserable. Think about every single corporate IT policy that exists and apply it not just to your desktop/laptop/phone but to what you do on that desktop/laptop/phone.
Security is about management of risk.
I'm going to repeat it again - we do not have a security problem with software. We have a risk management problem.
There's absolutely no reason for Marriott store information on previous guests past certain statue of limitations. In fact, they could probably offloaded it to Iron Mountain after 180 days. Storing it online has a certain risk profile. That risk was not correctly evaluated ( probably not evaluated at all ) and hence it was not minimized.
Storing credit card information ( even encrypted ) after the card was charged and transaction creates another risk profile. It also was not evaluated and it was not mitigated.
Businesses are obsessed with data without understanding the risk.
If developers demand that the tools they use are better built, then the market will deliver tools/frameworks/etc... that are secure from the start.
"Good" coding has become "good enough" coding, and the problem exists from the bottom of the stack to the top.
This is never going to happen because what is considered secure in one place is not considered secure in another place.
> "Good" coding has become "good enough" coding, and the problem exists from the bottom of the stack to the top.
Because it is about risk management, not about absolutes. It is absolutely irrelevant that a smart samsung TV that I have in my office has garbage security because it is used as one thing and one thing only - dumb 48" HDMI monitor not connected to wireless network. Its Wifi antenna connector has been cut. It matches my risk profile.
Most professions and companies are (at least in theory) held accountable for their impacts.
To stretch the car/driver analogy, you could limit all cars to 10 mph so that they can stop fast enough when a deer runs into the road unexpectedly, but that's probably not worth the tradeoff.
Pedestrians, on the other hand, are a predictable fact of life that you need to deal with when you get in a car. So are bad people on the internet. If you put something on an internet connection and aren't constantly aware of that, you should not be putting it on the internet.
There are a lot of really stupid mistakes made in a lot of these data disclosures that a competent IT team (and dev team) can prevent from happening. The current state of things is that there are hardly any consequences for losing people's data, just make a bulk purchase of credit monitoring and call it a day. This is cheaper than actually hiring the right people and implementing the correct processes.
Right, which is why we should increase consequences when there are data breaches so companies may actually care about them when they happen.
Why do you think customers are ready to pay extra for the extra data security?
I can see a time that software developers (leads at least) will need to be chartered just like someone that designers a bridge.
Does such a world even make economic sense after accounting for the opportunity cost of the time most that building designers would otherwise spend actually building funky new shapes?
Investing in solutions that assume buildings will collapse seems reasonable to me.
Sql injection is bad but not "a bridge with 50 cars collapsed over a city" bad
1) There are 150 million vehicles which can be remotely controlled via the vehicle manufacturer's software, which has generally mediocre application security.
2) The software in question is vulnerable to SQL injection, allowing up to 150 million vehicles to be remotely commandeered by a small group of attackers.
3) No hostages are taken and no owners of cars are deliberately harmed, because this is an application security scenario and not a kidnapping scenario (which is orthogonal).
The scenario you've posed is oddly florid...thinking through it, no, I don't think the robbery of 150 million vehicles is as serious as a bridge collapse with 50 (presumably occupied) vehicles on it.
Speaking more directly to the point - I think this is a really poor comparison. Logistically speaking it's hard to take seriously the idea that 150 million cars would actually be stolen because of any single SQL injection vulnerability. SQL injection is really bad, but it doesn't directly result in injury or loss of life. It's also hard to conceive of a situation in which SQL injection has the potential to cause systemic collapse like you're describing...maybe SQL injection to a database containing credentials that have write access to a server which can launch ICBMs?
In the modal case, I think it's okay to admit that application security is not as serious a concern as architectural stability. But this entire discussion is pretty much a sideshow; we can just all agree that security needs to be taken seriously and that some bureaucratic scar tissue is okay to make that happen.
In any case, the damage to Iran from the hack was not as significant as building collapse.
That's a pipe dream. Instead we should take advantage of public-key cryptography, so that authenticating to one company does not leave behind infinitely reusable credentials for others.
Right now, there are few penalties, outside of a brief reputational hit, for large firms that lose control of customer data.
But that's not the worst of it. The Economist here is doing a static analysis, oddly enough. They're making the simple observation that if things cost more or have more risk, they get more attention.
That's if they have more risk today. Once you collect data, it doesn't go anywhere. Every bit that sits on your servers can easily be copied to another server, today, tomorrow, ten years from now. Do you know what all the bits are on your computers?
This isn't copyrighted DRM or porn. You could have a blob hashes and userids. If I put that on your computer, would you know? Could you be expected to find it? Know what it was?
As Facebook and the other platforms are demonstrating, this data continues to have value many years after it was collected. And once somebody gives some data to you, it's effectively both invisible and trackless. Over long periods of time, your cost becomes infinity to maintain this risk. Meanwhile, attack vectors get better and people come and go out of your offices all the time. Could you manage that risk? Forever?
I can't think of _any_ sensitive data on the web that's stayed safe. Why would attaching any amount of value change that?
That's why GDPR happened. "Ok, if you're not going to do anything about it, we'll make you do something about it."
So you're not taking the economists point of view at least from the perspective of the free market rather you're thinking about which economic levers you could pull to effect change from a regulators point of view.
"There are two types of companies: those that have been hacked, and those who don't know they have been hacked."
[1] https://archives.fbi.gov/archives/news/speeches/combating-th...
[2] https://www.networkworld.com/article/2952184/cisco-subnet/jo...
Perhaps in the digital world as well, intrusion detection is more valuable than intrusion prevention?
You’re right. These companies should absolutely have to weigh the cost of keeping data because they overestimate their ability to keep it safe.
i.e., instead of the traditional "what are the [last 4 of] your SSN, and/or we'll tell you three things that may or may not be in your credit history and you have to fill in the blank on each of them"...
...why not just use 2FA?
You give everyone a TOTP code on a separate card but tied by the government to your SSN, passport number, and state ID. You provide a government mobile app that they can use if they don't want to use a 3rd party one. When some third party wants to verify your identity, there would be a heavily secured, simple, autited government server that you'd use the app to auth to (ssn + TOTP), returning a temporary auth code/passphrase, stored for 1 day and associated with your SSN. You give that temporary code to the third party, which then verifies that temporary auth code or passphrase with that same government server. You could have an additional voice phone channel to get the temp codes, for people without smartphones.
If your TOTP code card and device are both lost or stolen, you visit in person to get a new one just like normal. Anyone who sees the card can impersonate you, but you shouldn't be carrying it around or waving it around, and even if stolen in individual cases, the scheme eliminates mass identity theft.
U2F could be an option, for anyone with a u2f-capable hardware security key or smartphone, but I'm not sure about mandating u2f because compatible hardware has a non-trivial marginal cost.
Went into force a few months ago.
This very case is already an example of overreach. The only reason a hotel needs someone's identity is in case they trash the room and skip out. There is absolutely no reason that it should have been kept after checkout, except that we've been groomed to expect this surveillance based on payment cards being similarly broken.
I can see the possibility for reasonable progress in the EU, where a government ID could carry rules that it couldn't be involuntarily used for business purposes (and assuming that would actually last). But in the US, the government will mandate some base system and then let companies abuse it ad infinitum - even social security numbers are already way too much.
If a forum had the option of requiring real-world ID, they'd make the reasoned business-case tradeoff of whether that's likely to improve the forum/business (less trolling) or worsen it (far less signups because people want to be anonymous on that particular forum).
And as for hotels specifically, they require a real identity for public safety, so police can (not just at check-in, but even months or years later) determine where someone stayed in order to solve cases of murder, child trafficking, or other violent crime.
There's this gravely mistaken idea that a business's interests are fundamentally based on serving customers' interests. But both sides of any transaction have diverging interests, and in the real world we see industries uniformly implement arbitrary customer-hostile practices rather than compete. This is especially true when the customers' downsides are not easily quantifiable - see the entire advertising-surveillance industry.
And sure, there is always some prudent-sounding reason why more centralization is needed (essentially the "God narrative"), which is exactly why the safety-above-all ratchet moves ever forward. But in the free world this type of thinking is a red herring - the same scare-reasoning can be applied to mandating that every person have a machine-readable ID code tattooed on their forehead, and this only seems unreasonable because it's not present custom.
We need tough, enforced penalties for data breaches, plain and simple. It's a negative externality, just like pollution, and so can only be controlled by regulation.
No.
Your leaked data does not hurt me. So it is NOT like pollution.
If you do not like your data on the internet - do not give it to companies you do not trust.
> can only be controlled by regulation
Your claim is wrong.
Companies behavior is controlled by customers demands. The balance between security and convenience -- is not an exception here: customers demand define where that balance is. There is no need for the government to intervene in this case.
Anyway, these companies are bad at their job as evidenced by the breach happening. And I definitely think we're past the time where it should be illegal for companies to even ask for passport numbers, DOB and social security. A phone company, a hotel, need none of that. They just want it. Big difference.
What we need are more options to transact anonymously. This "show ID for everything" culture needs to stop.
I really don't understand why so many companies think they need so much information about me. Or even if they do need it, why such disparate data as passport numbers, credit card numbers, email address, gender, and home address would be stored in the same database.
Is there a law that requires hotels to collect all this data? I've stayed at some cheap motels where they glanced at my driver's license and accepted a couple of $20 bills, and I got a key, and that was the entire transaction.
If companies knew that there was a database that everyone has access to with all the data you need to signup for new sources of credit for 50% of US residents, there would be a very strong financial incentive to actually fix the problem.
https://phys.org/news/2013-09-lexisnexis-breach-earlier-year...
I'm preeetty sure they source DL data from some state DMVs.