It's not victim blaming because the victims are the patients. The people who were in charge of securing the records and left the creds as root:root are not victims.
It's not victim blaming because the victims are the patients. The people who were in charge of securing the records and left the creds as root:root are not victims.
We have to stop designing systems where if one administrative task is mistakenly skipped, the result is catastrophic. Imagine if when you tried to start your car that if you didn't have the brake fully pressed that your car blew up. Would you say "Oh, wow, how irresponsible it is to not fully press the brake"? No, you'd blame the manufacturer for building an exploding car.
Systems should not start if strong admin credentials are not the first thing that are set up.
If you are hired to secure a system and leave the credentials as root:root, you are derelict in your duty. Period.
If there is a system with external access, someone set it up. It is the responsibility of whoever setup that system to ensure access controls are in place. The barest minimum of that is to change the default creds to something unguessable.
A better analogy would be accidentally crashing the vehicle - an action resulting from negligence or incompetence rather than some 1/1000000 chance of your car exploding due to a failure in functional safety. If someone is operating a vehicle in a manner that it was not intended to be used should we blame the manufacturer? You expect litigation to follow someone forgetting their keys, driving their car into a lake, or running out of gas on a busy freeway?
The solution should be to mandate more certifications and security audits for high-risk organizations. The safety mechanisms should be legal and not technical; you shouldn't be permitted to operate a business dealing with sensitive data if you haven't been audited. Delegating more responsibility to the system architects doesn't solve the fact that you have incompetent people performing the administrative tasks and malicious actors abusing this incompetence. It isn't about someone making a mistake, it's about someone being irresponsible in a security sensitive environment - something that should carry severe legal repercussions.
Forgetting to change the default password on a system before starting it up and putting it into production (negligently or not), is not a very "obvious" type of failure. Hey the software is working! People can us it to accomplish their daily tasks! Everything is fine! There are basically no signals to the average, non-sophisticated user that something is amiss, for the vast majority of security vulnerabilities/misses.
So the real problem IMHO, is less about addressing systematic lack of competency or lack of oversight or licensing or things like that, and better tackled as questions of better UX, of failing fast and transparently to the user, or of making invalid/undesired states impossible (and user education yes, to some degree... but cars really do not require that crazy of an investment in training to operate, though different countries certainly set different expectations/standards). These are the sorts of problems that tech is used to solving, that the tech industry is optimized around solving. Of course, for tech to care about working on these problems, requires market incentives to be there (and by and large, the incentives are not there today). Which is what one of the GP ideas about fines and insurance costs/premiums is trying to address.
Similarly, I don't hold any credence to a black hat saying "but look at how insecure they were".
People hired to secure records that then do an exceedingly poor job are not the victims in this situation. Victims == patients.
In your analogies of rape/murder, the (almost) equivalent would be if there was a doorman at an apartment building who was supposed to verify the identity of everyone entering the building, but failed to do so, letting the unauthorized perpetrator into the building and thus allowing the victim to be raped/murdered. It was literally his job to prevent such a situation, and he failed. You maintain that he has no responsibility in this matter?
Probably because the OC had already hedged:
> if true, I see two quilty parties here.