The victims here had an obligation to those they worked with to take reasonable measures to prevent and mitigate this sort of thing. Just because something bad happened to them doesn't relieve them of this obligation.
It's possible for more than one party involved to be in the wrong. Just because the victims screwed up doesn't mean the perpetrator is somehow morally cleared. Nor does the perpetrator clear the victims of their carelessness.
Edit: Since apparently people are taking this to mean I think companies should withstand a dedicated attack by China, I've gone wrong somewhere. I don't mean that. I was talking about responsibility. They can both be responsible and not be negligent. What I expect is them to help clean up afterwards. Just because they failed in an understandable way doesn't mean they get to avoid taking actions to ensure the damage is minimized.
But they have a duty after the fact as well, to ensure the damage is minimized. That includes actually telling those potentially impacted what is known, etc.
IBM is not to blame for the initial attack. But any further attacks that result from their silence can have a good share of blame laid at their feet.
> according to the indictment, it was a few spearphishing emails with .docs attached, followed by keylogger and other malware installation.
Junior Sysadmins straight out of a bootcamp can negate that.
Not sure how on earth people expect companies to defend against that.
And all it took was meaningless buzzwords which almost all enterprise companies at least do already. It doesn't make one iota of difference when your vendor equipment or services are compromised.
You mentioned Cisco in another comment. Why buy Cisco if their stuff is known to be insecure or not proven secure? If not knowing high-security, I'd consider genua just cuz they use OpenBSD at the core. There were two others using INTEGRITY RTOS, one Sentinel's HYDRA and another discontinued, with both having few buyers. There's still going to be attacks but way less of them choking attackers further year after year. Hell, even leaks in CPU's were found from 1992-1995 using these same methods as LOCK et al in VAX VMM. We knew then with companies and security folks just ignoring them because those high-performance, lower-cost CPU's let us do some awesome stuff, right?
We're not getting hit because of ridiculous resources opponents put into 0-days: we're getting hit because of ridiculous resources put into known-insecure components and methods after people with those resources ignore stuff that works, often letting it die off. Totally, different problem. When phrased that way, one starts thinking maybe they should be regulated to use what works or liable for some of these decisions for ignoring what works using what's high-risk. I favor regulation after seeing positive results in TCSEC and DO-178B markets in terms of assurance activities.
Edit: spelling.
Almost all companies simply do not have the capabilities to defend against state sponsored attacks and are already taking reasonable measures to prevent and mitigate. When you have undisclosed exploits being used against third party vendor hardware to attack the company what can you reasonably do ?
It doesn't mean they get to clean their hands of the whole thing either. They failed, and that's fine as long as they weren't being negligent. But they are still responsible for doing what they can to minimize the damage. That means, for one, informing those impacted about what is known.
So, just to be super explicit. I don't expect a business to withstand a nation-state attack. I do however expect them to do what they can to minimize the damage afterwards.
In this case it was spearphishing infected .docs. If corp security can't deal with that, they've got bigger problems.
"I don't believe you." You can't just change the organization, culture, and procedures of a company just by throwing money at consultants.
That's like saying a big family can solve their feuds and mental illnesses just by writing a check to team of group therapists and lawyers.
Oh wait you can't. Which is why we had to turn to our government intelligence services to provide assistance.
So stop pretending like companies can defend against state sponsors who are buying 0-days for $100k+ like it's candy.
https://lobste.rs/s/o6x9b3/tech_s_masturbatory_historiograph...
I described what I learned about how high-assurance security builds stuff here:
As I often said, compare anything from security market advertised as secure against stuff on that list. If they're missing something, they're probably insecure. Now, I'm still not saying you can stop nation states and all 0-days. I am saying that most of the $100k 0-days are preventable with architectures like above with apps in safe languages with guards separating trusted things from untrusted things. Ada has also been around a long time with Rust getting popular now.
What makes most companies not use stuff like that isn't that level of security being unachievable: they just don't want to for management's reasons which range from arbitrary to sound practices in a profit-focused environment.
Security is hard. So hard that no matter what amount of money you spend you will still be vulnerable, but maybe a bit less so. There are no absolutes in this.
If, what you are saying is reality, what consequences can it have and what legal recourse can a client (corporation or private) expect in such cases? Who can be hold as responsible if sensitive data disappears? Does it need a new type of contracts when subscribing to a service?
Now, there may be a wrinkle. When discussing nation-state grade actors, there's a very real possibility that they may attack in ways that cannot reasonably have been protected against by most private-sector security programs.
What are we to think, to do, to expect in such a scenario? To what extent should be expect any company, even a large and wealthy one, to successfully fend off the full might of a large and powerful nation-state's offensive information security apparatus?
Again, you're absolutely and unquestionably right. Companies can, should, and must take reasonable measures to protect the basic human rights of security and privacy. There just might be some room for subtlety when considering what reasonable measures can accomplish.
What I was trying to say was that that doesn't relieve them of their responsibilities to minimize the damage afterwards.
Just because they can't be expected to win doesn't mean they should be able to wash their hands of the whole affair without trying to help.
More to the point, in what ways are the companies allegedly breached failing to live up to their responsibilities to help minimize the damage of a breach? What should they do in a scenario where investigations may be ongoing and potentially involving law enforcement?
Car thief crashes car into crowd of people.
Crowd of people sue you for damages because you didn't make your garage secure enough? Why didn't you hire a 24/7 security service to protect your property to decrease risk?
I think it’s more than fair to say that reams of personal info stored by companies is such an attractive nuisance.
I get that it's liberating to disclaim responsibility for the consequences of anything we do, but that isn't how the world works. At some point (however far) you are held responsible for your negligence.
Or, how about they explicitly tell their customers that they can’t keep their data safe and might be a target of an attack that harms the customer?
I’m ok with either option.
There is an implicit expectation/contract that if a company is collecting your data it will keep it safe. If it’s not going to do that and will not do anything afterwards to repair any damages caused then they should just delete it after using that data or, advertise they can’t keep it safe and let the customer decide.
This means it is notoriously complex and nuanced, but it's not going to be overturned by boolean strawmen.
Edit: Moral of the story, since perhaps it's not obvious to all, is secure your dangerous property, cars, guns, band saws, computer networks, or otherwise.
But if you know that people steal packages off of porches in your neighborhood, and you leave a package out there for weeks, you're at least being pretty unwise. You're not morally at fault, but pragmatically, yes, you kind of are.
[Edit: That is, your actions are not well-suited for the kind of world that we actually live in, and that you know that we live in.]
You could have set up a different causal chain that would have prevented the theft. Of course that doesn't mean that society can't blame (and punish) the thief.
You want to explain how you defend against that ?
1. Put valuables in a low-rated safe whose door opener is network accessible and itself low-rated.
2. Whose alarms suck at identifying and responding to actual breaches by even the most common methods.
3. A thief breaking in who uses the most common methods that the safemaker or company didn't try to stop. They did spend a fortune on unrelated stuff.
4. Various designs and implementations that weren't using methods that often prevent or detect backdoor attempts in favor of methods that let backdoors slip through.
Also, this is a company that makes billions in profits a year. They have the money to both develop and build highly-secure systems, including safes. They keep not doing that or not using what high-security they build. They keep using low-security stuff year after year after year. They could defend against those problems by doing more of what works and not using low-rated, often-vulnerable stuff for protecting secrets. Just a hunch on my part. ;)
This is like defending a teacher who left a loaded gun on their desk because they are the victim of theft.