Security is difficult. Microsoft is supposed to be skilled at preventing data breeches and exploits, but apparently not. What can be done to prevent this sort of thing?
Security is difficult. Microsoft is supposed to be skilled at preventing data breeches and exploits, but apparently not. What can be done to prevent this sort of thing?
It's a wildly asymmetrical relationship that means 9 billion people get a try to knock you out and your team of what??? 25, 50, 100, 1000? Security specialists have to see everything possible and plan for any and all possibilities.
It's never going to happen.
This is the simple reality of the internet and I'm sure you know this, but I saw your comment and thought I'd add this for the next person who may not realize this.
I'm personally curious to know, because I'm no SecOps; if there is even a theoretical solution to the internet that would have greater integrity for the users or if this is as good as it gets.
Please don't do this. Something can be done, we all know it, but for some reason don't think it's possible? Prison sentences should have started with the Target CTO in 2013 (at the very latest), but the more the public is cowed by shrug emojis, the less likely companies will protect your data for anything other than commercial advantage.
But we do need much more oversight and serious punishment for companies that lose data like this.
US soldiers fight in combat knowing failure to obey orders can land them in jail for years. The US Code of Military Justice is not fun, and you sign up for it when you join implicitly. Is there an armed service staffing problem?
Our general US legal system is flawed, but cops can go to jail for ethical violations and criminal behavior for actions that are integral parts of their job function. Is there a cop staffing shortage?
I have argued this, ironically, about US Congresspeople: if we have a volunteer army with stringent legal codes with special punishment by virtue of their job, serving us, why are other classes of people not worthy of higher standards and why do we suspect people will shy away from that? How can we pay others more for higher probability of incompetence and less repercussions?
I am not trolling. When I suggested this shows the power of commitment in volunteer armies and I wish Congress had that kind of self respect people tell me I'm nuts. I would like a CTO and security industry jobs to mean something.
And considering the fact that no amount of competence will protect you from a sufficiently motivated and resourceful hacker, seems unfair.
Now if we come up with a framework and a security checklist that must be followed and certified by the CTO every quarter or something, and they don't do it, or lie, then sure, jail them.
We rely way too much on Other People's Computers to do stuff. The only real way to avoid issues is to make them technically impossible, not to rely on laws (that can be abused).
(yes, i know i am asking for putting the cat back in the bag long after the cat's own grandchildren have died...)
with enough attention on information theoretic security (or unconditional security), things may change