Should you delete your Patreon account after they laid off their security team?
soatok.blog
soatok.blog
An earlier employer had a single person in charge of security for a company with 50000+ customer investment accounts. Oh and the one that was there when I started was eventually discovered to have two full time jobs, which worked because he had unlimited vacations. After that person was fired, the replacement did nothing but run a few scripts every day, and our databases did not encrypt anything, and they argued for months on whether to buy disk encryption software instead of the just encrypting credit card numbers (which meant various applications had to be modified and no one wanted to pay for that work).
So if Patreon dumped their entire security team (or just one part, it's not clear) makes me reminisce about stupidities... not much has changed.
Unless some major creators that use Patreon begin a very public exodus from the site, I'm not sure too many regular users are going to be leaving though. The blackmail risk of having your subscription history leaked won't even register for a lot of users.
It's really hard to get people to take their monthly contributions to a Patreon competitor. The inertia is really hard to overcome. So in a sense its kind of like lock-in - if you move you'll give up some % of your income.
▶ The ability to build an all-in-house or largely-in-house program is a luxury where largely every staffer, even staff-aug over time, can have the necessary institutional context to understand whether a threat is being realized. If you can do it comfortably and with a focus on automation, you probably should.
To analogize: a castle has its own moat, its own hard walls, its own defense team, retractable entrances, traps, labrynth layout, etc. etc.
▶ A fully outsourced program doesn't have the necessary institutional context to catch edge cases or even a substantial number of common or uncommon threats and outcomes. Especially when the services used are multi-tenant, which is where a lot of the cost-savings come from for outsourced programs. So for an outsourced program to succeed, you'll probably still need a few hands to add that missing context or to work together with the service providers to help them automatically understand that context.
To analogize: a house in a gated community shares the same security team and light barriers (fence, wall, whichever) as other houses, but that team might not be as well versed on what to look out for. And the house itself may have alarms, but none of this may be all that great at deterring a common smash-and-grab.
---
Patreon had what, 1%-ish of their staff doing infosec? I'd venture that a lot of them performed functions such as automating appsec, automating integrations with service providers, etc., understanding privacy and security legislation and obligations, and served the role of contextualizing security between their internal product teams and external security service providers.
Without a dedicated in-house team, no matter how small, I'd bet dollars that they'll be compromised again in short order. And I've advised people relying on Patreon to seek alternate services as a result.
Technically a tool like Snyk or Dependabot is a third-party security vendor, but would you trust your financial & personal information with a company that says their security posture relies solely on those tools?
What's visible once you are past the hyped language in the article is that Patreon had a 5-person security team, and MULTIPLE security vendors up until this point?
Doesn't that look like too much for a small startup to start with? And if one argues that 'No amount of security is enough', then HOW many security vendors does anyone need?
Is there an objective measure? Like, does the amount of manpower that a security vendor should determine whether that vendor is enough? Or the number of industry-renowned personas that work in that vendor?
What happens if one player buys out all those security vendors and combines them into one single large vendor? Will that be enough?
...
So basically there is no objective criteria for this. The proposition is 'less security is bad', but nobody defines 'the right amount' of security objectively. So even if Patreon or anyone else is using a top-notch competent security vendor that handles all their stuff, it wouldn't be enough because... well, this is a chance to do some hype, obviously.
The proposition of the article in canceling Patreon and 'moving somewhere else' is also very dangerous and it feels like self serving.
Cancel Patreon and go where? Set up a subscription service yourself? And deal with all the chargebacks, fraud, refunds, financial compliance, and gasp sales tax collection and clearing? Or, one of the much smaller Patreon-competitors who have even less backing and organization behind them? So move from Patreon to... 'smaller Patreon'?
Which would easily put someone in hot water regarding actual legal responsibilities that can land one in large fines and even court sentences, by the way. People think that just because they have been making some side money here and there on the Internet and this was not something that the tax agencies and governments would bother to look into, things will stay the same if they start making such regular, noticeable income. It doesn't work like that. Things get serious.
Because now the money that you are making with your creative activity is not occasional 'gig money' that is paid you in cash somewhere, totally unaccountable. Its regular, trackable income that may land you in very hot water if you end up getting called up by your tax authority randomly in a few years. There is always the chance that your government may start a major sweep to weed out tax-dodgers so it may not be even random.
So such propositions like in the article 'Cancel and do something else' feels like random retorts from people who don't actually know what they are dealing with - laws and other people's money.
...
Even the prospect of having to set up and maintain a billing system should make people shudder at such a proposition. Its all fun and games at the start when you are setting up stuff. Not so much when keeping it updated and compliant takes a considerable chunk of time 2 years down the road. Forcing you to do deal with those instead of doing your creative activity.
I was not criticizing people for their take on the subject, but rather for coming after the author instead of discussing the article he wrote.
It's the same feeling when seeing a leather clad lady hauling someone's granddad on a leash around town. I respect it, just don't make me part of it against my will. I'll make a note to skip this site in the future.
https://soatok.blog/2021/04/02/the-furry-sexuality-blog-post...
This comes up a lot, but: Furry isn't my kink. I hope that settles it.
My argument is that furry isn't inherently any more sexual than anything else. To call it a sex/kink thing is not a meaningful argument.
After I tweeted that I deleted my Patreon (to which I paid like $700/month to various creators), several people asked me (publicly and privately) whether they should follow suit. I wanted to offer a calmer take.
Since there was discussion on HN about this topic yesterday, I thought the folks here would appreciate the perspective.
Disregard people who are easily offended, your work is pertinent on hacker news, and your SFW imagery is not against any rules.
When people post websites to Show HN the majority of the comments are usually not more insightful than "I don't like this button, make it a different color."
>The website you’re reading is a furry blog before it’s anything else.
I don't think anyone should hate him for that. But neutral commentary I feel is okay. Otherwise yeah some people are proud of their identity
I'm going to export all my files and drop the account i think. Need to tighten the belt anyway.
I would even guess that for a large breach like the one T mobile had, most of their customers don’t know about it. And if they do the thing they care most about is trying to get their cash payment because “free money.”
I’m not saying that’s how it should be but that’s how it is. Companies make decisions every day that are bad for their customers and everyday unless the customers are majorly inconvenienced they simply don’t care. Or maybe I’m in a bad mood today and casting everything in a negative light. Or both.
If you don’t care go ahead and post your social security number in this thread.
For me, the password is unique, the name and billing address is public record, and my bank protects me from credit card fraud, since using one requires handing the number out multiple times a day. The only thing that bothers me is the IP address, but that was leaked in other breaches, once a few years ago, and twice this year. I think this is the same for most people.
(Nevermind there are no new IRS requirements.)
Is it a meaningful number of people? I couldn't say at present, but to talk in absolutes is silly.
so now i have to think it’s a reasonable guess that a security team member found out early and even possibly leaked it, even if only internally like to their boss. to contain it the whole team had to suddenly be let go.
that’s beside the point. just a random theory. in this context, the point is that there’s been no follow up on the security layoff, no tie in with the larger story, so yeah no one cared
If my CC is compromised, i'll notice in my monthly statement and report the bad charges (this has happened twice in 10 years). ...once from using the card in eastern Europe and the 2nd time at a hospital recently.
Not using services online because you're afraid of a breach is highly inefficient.
Better to share as little as possible and have consistencies when there are breaches.
What were they doing?
I worked on a major product that was known for our security benefits, and we didn't have a team of five on "security." We made sure that everyone understood best practices, and eventually had a "head of security" that oversaw our product and other products as well.
So, what was the security team really doing?
If you're good at your job so there's no issues: "What are you _really_ doing?"
If you're bad at your job so there's tons of issues: "What are you _really_ doing?"
And to be painfully honest, it also encourages coverups and lying on reports. As a security engineer at another vendor who has worked with these MSPs and their clients I have seen a lot of things that went sideways and the MSP wants to cover it up and it makes responding to an incident really hard.
If outsourcing credit card processing to Stripe and Paypal is not abdicating your responsibilities, that also isnt.
There's one CISO school of thought that believes the job is to run every automated scanner they can get their hands on, report results to engineering and job is done. That can certainly all be outsourced.
Another school of thought (where I inhabit) is that sure, you need to do that, but to really have a secure product or service it has to be built ground-up with security as a core requirement. You can't outsource that (ok you could but it means having expensive consultants sitting in with the engineering teams day to day, at which point it's far cheaper to have an in-house security team).
Most of the comments in that thread are about how layoffs like this happen if there is a major screwup; or how Patreon might be able to outsource security for significantly cheaper.
Top comment at the moment seems pretty reasonable.
We might be more accepting of furries than our non-queer counterparts, but that doesn't make us furries ourselves. Claiming furry and queer is anywhere close to a a perfect circle venn diagram is way off base.
I didn't say:
* all queer people are furry. Most A are B is not all B are A.
* that the Venn diagram is anywhere near a perfect circle. In fact, I said that's not the case.
HN's guideline on reading things charitably could have saved both of us some annoyance here. Try again. It's absurd to think I could mean the things you thought I meant.
>> "Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith."
It would be absurd to suggest queer people are mostly furries, so that interpretation is implausible. Act as though the person you reply to is rational, and you can discard the absurd.
A strong, good faith reading could reasonably assume I don't know anything about Venn diagrams and didn't realize all the circles are equal when I posted that. I'm assuming good faith, and that's why I didn't just flag their post for trolling. Maybe they're not trolling and just don't practice this principle.
https://furscience.com/research-findings/sex-relationships-p...
Furries on the whole are accepting and welcoming. For people who have faced discrimination in one form or another, the fandom is a place where one can belong and simply be who they are.
This furry-to-IT pipeline has been running since the beginning of the World Wide Web as a thing people put money into.