Security is a complex issue that requires custom, expensive, and ongoing solutions. So companies run by non-security professionals are going to trust the relatively cheap programs offered by these large providers.
Take startups. Having a security breach won't kill your startup. Being slow to market will.
Without a solid ROI, it probably won't turn into a gold rush anytime soon.
On the other hand if we cared about security we would not rush to assign a long lasting hard to change number to a person, and share it around... (Or worse in the case of SSN (for the U.S.) pick a number that is neither randomly assigned nor equipped with a validation mechanism.)
Anyone know the current state of the industry?
Large corporations are run by business majors who often have a disdain for computer science. Usually this leads to not hiring the top security experts (either through lack of knowledge or not wanting anyone smarter than themselves at the wheel).I've personally seen this at a few jobs. It can go both ways as often CS-saavy startup founders are the same way towards business majors.
They're already using a system that works for them, why bother changing to something else?
It may be worth considering that adapting said FLOSS software, doing the requisite custom integration work, and then doing a large migration successfully might all be perhaps slightly less free than the software you correctly and wisely point to.
The real costs and work is in the migration and adoption of new tools (regardless of the cost of the tools themselves).
Until there's a good reason to do so people aren't going to bother.
That said, there are fair number of common-sense low or zero cost safeguards any technical employees could implement to help mitigate threats.
The cost isn't in the safeguards. The cost is in the governance structures (i.e. time spent by mid-level managers) that ensure the safeguards are followed and applied consistently across the organization.
Encrypting database fields is basically free. Making sure all database fields that should be encrypted are is an expensive process.
I believe it was in one of Henry Cloud's books on boundaries where I learned the idea that people roughly fit into three categories.
- they want to treat others well, and if you inform them of a boundary they've overstepped, they'll try to correct it
- they care about themselves within the framework of our society and laws, but are not keen on giving up anything for anyone else. If you want to enforce a boundary with them, you have to find a way to shift the consequences of their actions back onto them. Only if it hurts them, will they change their behavior
- they don't care about laws, society, decency, etc - you'll need guns and lawyers.
Right now it feels like many corporations are on a wide line between the second and third description above... what a sad realization!
The incident took place on the Starwood network (they bought starwood, a completely separate company with completely separate infrastructure), and this issue was discovered post acquisition and during the long running integration program (starwood had 2 breaches previously, so I guess it's not surprising). From what I've seen, if it wasn't for the controls implemented as part of the integration which formed part of Marriott's standard risk-averse approach to security generally, it probably wouldn't have been found for another 4 years.
It's complicated, and 99% of the "damn fool corporates and their evil ways!" comments are completely off the mark because they don't have the context.
The reality is that integrating another business is unbelievable difficult. Managing the (now significantly higher) infosec risks more so. You inherit a landscape with monsters you don't know about, and you still have to own whatever pops out. It's a really, really bad thing to have happened - make no mistake. And in time, the full story will out and opinions can be reached based on facts. Maybe they did screw it up. Maybe they could have done stuff differently. I don't think it's like equifax with a clear cut cause and effect, but a reasonably complicated ecosystem steeped in legacy systems opaque dependencies that is really hard to change.
It seems to be this generally accepted thing that whenever there is a huge breach, some people (aside from the person doing the breaching) have been utterly negligent, ignored all the obvious and really quite simple (I mean, just encryption all the things, amirite? duh!) and should be rounded up and shot at dawn. Perhaps - just perhaps - it's something that wasn't a result of negligence, and just wasn't foreseen because hard stuff is hard. Hindsight really does create the most impressive armchair strategists.
(no, I don't still work there. I left a few years ago. no, I don't think they're perfect. no, I don't think all corporations are evil incarnate looking to steal our data, only some of them.)
The fines for neglect of personal customer data need to be so high that the boards of these companies and their shareholders demand that their executives make security a priority.
HIPAA (https://compliancy-group.com/hipaa-fines-directory-year/) is a decent model and it does seem like security is taken more seriously in the healthcare industry in general. That being said, the actual fines are relatively low when you look at the size of some of these companies.
Anthem is one example: https://www.hhs.gov/about/news/2018/10/15/anthem-pays-ocr-16...
That was the largest HIPAA fine ever ($16 million) for a company that pulls in $90 BILLION in revenue each year and 79 million people had their information compromised in that event. That fine is basically a rounding error for them. Still, this outcome is better than what happens with most non-healthcare security compromises, which is basically nothing except "we're sorry, we take security seriously, and here is one year of credit monitoring."
According to their 2017 annual report [1], Marriot had $22.9bn in worldwide revenue. A 4% penalty on that would be $900M.
[1] https://marriott.gcs-web.com/static-files/057a8e1a-a5c5-4c20...
The question is probably if it is state of the art to encrypt passport numbers. If yes, then Marriot could be fine with a similiar argument of "the company knowingly violated its duty to ensure data security".
the grace period started two years ago until may 2018...
people seem to forget that the GDPR was technically already a law in 2016, it was just not enforced.
Does "select passport from customers" no longer work as a query? Or do you store an encrypted value in the table that you then decrypt on demand? Is the decryption performed by a microservice that add an additional layer that would need to be hacked?
That is precisely one model. In fact, there are hardened "vault" appliances designed for exactly this class of use cases. All sensitive PII is 1) encrypted on the vault and 2) replaced externally with a random token. Most of the time, the rule is that the plaintext PII is never removed from the vault. E.g. to compare a value, a new one is sent to the vault to (idempotently) to retrieve a token.
Done right, this gives you other features/requirements such as the ability to rate limit and set alarms on vault accesses. E.g. if someone were trying to brute-force retrieve vault data via token retrieval.
1. Most companies, even large ones, do not encrypt everything. Some do, usually because they have to according to some regulation of the space they operate in (HIPAA for example).
2. Passport numbers are a grey area. Is it public information? Is it private information?
3. Even if you encrypt your database, the key will most often be lying next to it. Unless your company really cares about security, because they have to by design, they will most often not architect an infrastructure that protects the key.
(4) the term “record” means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph;
[1]: https://www.us-passport-service-guide.com/is-passport-inform...
...what? A database stops working as a database if you encrypt every field
If you encrypt at rest/in transit (which you should legally) then you're only protected against a very limited set of threats
Encryption is not going to save you if you have SQL injection or webserver breech
Encryption is good but protects against hardly anything, usually physical attacks, do not try and encrypt at the application level, password fields are encrypted because you should never need to query it
Passwords are the exception not the rule
As engineers, we are awed when flaws like Rowhammer and Spectre are exposed, but the fact is that a lot more data is being exposed by very simple means. The fact that corporations are still being breached by these efforts is troubling. I think it shines a bad light on both corporate entities and security consultants.
This also means, disks walking away are always encrypted. We physically shred all of our disks, but humans can make mistakes.
If you are encrypting your passwords you are already doing it wrong.
There's a lack of attention at the executive and organization levels in these major corporations, so they're not set up to deal with security threats in a forward looking way.
They tell developers to "not worry about it" and force deadlines on them that don't allow for doing things right.
I'm almost certain Marriott has security people telling the higher-ups that they need to do X to protect security, but if other companies are not subjected to that same risk, revenue growth is always going to win over security.
This will never change until governments start holding these companies liable with severe penalties that are not simply "the cost of doing business."
Companies seem to have no idea who is who.
90% of their IT staff's time was calling up their vendors support teams and convincing them to join a conference call together and then telling vendors from different companies to just make it work, whatever it was. They thought that was just how you did things.
Eventually we told them "naw we're not doing that anymore stop eating our support team's time". They threatened to move on to another vendor and tried... but couldn't actually pull it off because... they simply didn't have the manpower or technical knowledge.
Once the file system is mounted the filesystem is unlocked. This is way things like LUKS which has bee around forever work today.