As long as -- cost of compromise < cost of security -- on and on this will go.
As long as -- cost of compromise < cost of security -- on and on this will go.
I agree broadly with regulations designed to raise the cost of security flaws and so on, but I feel like there's this expectation that if we make the punishment extreme enough, people will begin writing perfect software and operating perfect servers, and I just don't buy it. It seems sort of like saying if someone causes a production issue or accidentally leaks a database, they should be summarily fired. More likely it was a mistake, and we should understand why it happened so we can prevent it in the future.
What's discussed in this thread is whether the larger a company is, the more likely it's gross negligence. The irony to me is that every large company I've worked with takes security very seriously. The only gross negligence I've seen has come from startups that willfully disregard security practices in the name of moving fast.
Couldn't agree more. I've done security consulting for many companies of varying sizes. The large ones almost universally have massive security budgets, constant pentesting, and security audits/processes out the ass. They still get breached because security is fucking hard, no matter how much money you throw at it.
I don't buy in to the whole "if only those evil MBA manager types would allocate more budget to security and take security more seriously, they wouldn't get hacked". Every company I've worked at is scared shitless of being hacked, and have enormous security budgets. The management chain usually takes it very seriously. IME, a huge part of the problem actually ends up being the individual development teams who skip things like encryption because they think it's too onerous or they just think it's frivolous.
I cannot even begin to tell you the amount of time I have had to spend with developers arguing with them that they do need to do things like encrypt PII or enable HTTPS. "But it's only a small database of SSNs, do we really have to encrypt it? We would rather spend the developer time building something else rather than implementing encryption!" they say, and then spend hours/days arguing about it rather than just doing it.
This is a corollary to "nine women can't make a baby in a month."
That's not to say that breaches like this should just get punished by a slap on the wrist; this clearly must not happen. But especially when the company is so large you simply have an insanely large attack surface that comes with it. And it only takes one weak spot on there for an attacker to get in. People have casually carried out all data from Facebook, LinkedIn and even the NSA (multiple times!) - security at that scale simply is hard.
This is true. It is hard to design a CS backend that user user friendly and privacy cognizant at the same time.
However, the other issue is sticky habit of the companies to grab on to as much data as possible and keep it just in case. For example, this breach had SSN next to user's phone number, name and address. Why does it need to store SSN at the first place after initial verification? It is not necessary for most of it's operation. The only reason I can think of is if they want to report defaulted payments to credits bureau. Although, storing SSN can be avoided in a similar way, how payment APIs allow you to minimize handling of credit card number, of course you need support for this from credits bureau. If they aren't cooperative, you can still design the system in compartmentalized way, that simply does not keep an association between SSN and other user info in one place, because SSN is used in very narrow scenarios. There is not enough pressure on the companies right now to do that.
No one over 30 takes this position seriously.
When I was young, I wasn't a fan of this sort of policy, since I looked at things less holistically, and on shorter timeframes.
Holistically, higher damages aren't anticorporation, but just shift the ecosystem. Over time, companies who treat data securely will have a market advantage. Different, more secure programming practice will evolve, and companies will innovate and compete in security.
My thinking changed around the time GDPR passed. Before, I thought policies like that were anti-corporate. After, I saw how they changed market forces, but economies did just fine or better. Externalizing costs isn't good for economies.
They shouldn't be externalized onto the victims. The cost will, by principle, always be externalized to their customers, since that is were the money has to come from.
Company A has good security, which adds $5 in your costs.
Company B has poor security, which doesn't, which will lead to $500 down-the-line from a security breach and identity theft. It charges $2.50 less and otherwise has an identical product.
You have no way to know that. You will go with company B, and you will split the $5 gain, where you save $2.50 and they take $2.50 more in profit.
Company B externalizes costs onto the customer. Company A's customers have higher initial costs, but they wouldn't be defined as 'externalized.'
The situation we have here is clearly company B. So we have two options:
- Let the victim (who is or was a customer) pay the $500
- Let the company pay the $500. They need to get that money [0], so they charge their current customers more money.
Either way, the bill goes to the customer. The only difference in the second scenario is that the company needs to increase prices, which will hurt them in the long run and (hopefully) justify the additional expenses in security. But they can't create money out of thin air [1].
> Company A's customers have higher initial costs, but they wouldn't be defined as 'externalized'.
You're right - I was wrong about the definition of externalized.
[0] Technically, they don't - they could go bankrupt. But that would be the first scenario all over again.
[1] Unless we're talking about a bank, of course ;)
If company B tries to charge customers an extra $500, they'll be more expensive than company A, and customers will go to company A. They'll exactly go bankrupt. If they could have charged customers $500 extra and kept it, they would have done that from the get-go. The money won't come from customers, at least in a market with any competition.
Where will it come from? Well, the money will ultimately come from company B's investors. There are several mechanisms by which this can happen:
- Company B has a billion dollars in the bank. It spends $500 million on damages. It now has $500 million in the bank, and is worth $500 million less.
- Company B has zero dollars in the bank, but an otherwise solid business. It issues new equity, diluting existing equity, to raise $500 million. Existing shares are worth $500 million less.
- Company B has zero dollars in the bank, and a negative net worth. It files for bankruptcy. A court reorganizes it to pay the debtors (e.g. the customers). Old shares are worth $0, and the company is now owned by its debtors -- it's customers. The shares aren't quite worth $500 each, but customers get as much as possible, and the business keeps chugging along. No one loses their job.
Once investors notice, they'll start to include data security into company valuations. Insurance companies will do likewise. Keeping poor security will decrease profits, and security will improve. On the other hand, I don't think many companies will fold -- in the sense of letting customers and employees down -- based on this.
For context, I'm very likely in this breach, but it wouldn't make me any happier to hear T-Mobile was shut-down tomorrow.
And a corporate dissolution isn't the outcome. The outcome is that T-Mobile goes into bankruptcy, with its customers as the debtors. The outcome of that is that a bankruptcy court divides up the assets to maximize payout to you.
Most likely, this means:
- T-Mobile, as an entity continues to exist, as-is..
- Shareholder value is wiped out...
- And handed to customers, as the customers become shareholders.
T-Mobile has a 180B market cap, which probably means you acquire stock worth a grand or so.
Right now only the company is accountable as if it’s some sort of living creature, and the penalty is always money. Which as you aptly put, they have in abundance!
Either way, there needs to be far stiffer penalties levied against companies who don't secure their systems better and lose sensitive customer data.
Let’s not pretend there isn’t a deterrent.
[0] - https://www.google.com/amp/s/www.businessinsider.com/breivik...
> The trove includes not only names, phone numbers, and physical addresses but also more sensitive data like social security numbers, driver's license information, and IMEI numbers, unique identifiers tied to each mobile device.
Now, this seems like a lot. I hope we will see a detailed technical analysis of the break eventually.
>and possibly change name
>I wouldn’t use a compromised IMEI phone for 2FA
Why?
>get new SSN
That might be prudent to do, but at worse it's a few hours of hassle. I searched around and it looks like all you have to do is fill in a form (https://www.ssa.gov/forms/ss-5.pdf) and supply the required documents. At US median wages it's a few hundred dollars, max.
>the potential losses from the selling of this information have any real limit.
Well not really? Suppose someone crashed into your house, making a hole in the wall that allows thieves to steal potentially unlimited amounts of goods from your house. Should the driver be liable for all thefts from your house in perpetuity? Or only between the time of the crash and when you can reasonably get the wall fixed (or in the case of identity theft, changed your SSN)?
Even if you do get a new SSN I wonder what the process is for changing it with the credit bureaus.
2. hire cyber-mercenaries to hack company
3. ???
4. profit
Instead of just cash
Then management gets replaced
It absolutely would not. Yes we would see greater investment in cyber security and it would pay dividends, but the idea that we can totally eliminate data breaches if we just try really super hard is unrealistic.
If there was sufficient regulatory force to induce companies to make the choice between not hoarding data or not existing then I'm sure that business would carry on as it has for millennia.