Information Security: "We Can Do It, We Just Choose Not To"
hezmatt.org
hezmatt.org
You enter your abode via the public. It's really not hard for someone like a stalker or private investigator or paparazzi to figure out if they can find... you. That is to say if you go in public. It's readily available to anyone who actually wants to seek it out, and it's something you do in public. It's not particularly private information in the practical sense.
Every time my address is leaked online, I am not worried in the least. I don't really need to do anything. It's readily available on any number of information sites online anyway.
When my credit card gets leaked, it's a major headache regardless of if I am liable for charges. Now I have to cancel my card, change all my automatic subscriptions, reenter it on every single shopping site. It will take literally months for all that to resolve.
The answer is that the bit of work - "really not hard" as you put it - actually can be quite hard, and it is a real deterrent.
You don't really care about whether something bad can happen... you can about whether it is likely to happen. It's a probability. And making it hard to find your address reduces that probability.
Also I would suggest that HN members are unlikely to be stalked. You might feel differently if you were a Twitch girl or whatever.
If everyone treated it as easily available data, and stopped using the act of having it alone as "proof" of anything we could be much more secure. E.g. merely having someones address should not be enough to get their house swatted.
In its original context, relying on obscurity alone as your only defense isn't recommended when there are better alternatives like real authentication and encryption. Also, hiding isn't an option for things necessarily done in public.
But it's still defense in depth when you can do it. People can just show up at your doorstep and that's a hassle or worse.
There is also the crazy ex scenario. We should probably avoid assuming everyone has the same security needs.
But when it's in addition to good measures, then it generally improves security.
I used both obscure ports AND strong passwords or keys.
Whether we like it or not, in practice the obscure ports stop a ton of drive by bots.
Even if you are using a keys, the obscure ports stops the bot with a 0day exploit from getting in.
That's an oversimplification. Obscurity is generally a really thin layer of security - not nothing, but if people think of it as "real" security then they neglect other things and just have the inadequate layer that is obscurity. By way of analogy - if you add a 3-character password to a system, it is strictly more secure than without that password. But if you think "oh, I have a password, so I'm safe and don't need anything else" then you will get owned the first time someone takes an actual run at your security. A system that depends on obscurity is probably doomed to failure, but that doesn't make its value zero, just low.
I think that would go a long way towards solving the problem.
Please forgive me... I don't mean this as a personal insult; but a better system would be where you get fined $50 for being stupid enough to give them the data in the first place.
So … you don’t use banks, utilities, phone companies, healthcare, etc. and don’t apply for or accept non-anonymous jobs? This isn’t optional in many cases, which is why it really needs to be covered by legislation which shifts the cost to the company collecting that data.
Well that didn't come over as humorless, tone-deaf, pompous or over-sensitive at all, thank goodness. I'll just get back to grunting and waving a jaw-bone in my cave, eating grubs and worms and smearing myself with my own faeces, then, shall I?
Using weak passwords, leaving credentials where others can see them and downloading infected files can all lead to compromised data. Data breach insurance is specifically designed to protect a company in the aftermath of such an unexpected event.
Business correctly recognizes data breaches as a risk. The insurance industry allows companies to export that risk to them. Data breach insurance pays for the financial impact to the business as a result of a data breach. This does not protect customers and in-fact creates misaligned incentives between a business and its customers.
One solution would be to legislate that insurance is not acceptable for an organization to mitigate cyber risk. States and the federal government could do this by passing a law. I don’t see something like that getting passed though. The insurance industry and every business, both large and small, will lobby hard against it. You’d really need a strong grassroots consumer advocacy group to push hard for this, something that tells people’s personal stories to the media.
I’m not all “free market solves it all”, but it definitely works well at balancing money through the system. We just haven’t correctly priced a data-breach.
If we store credit card information we need to be PCI compliant. Let’s outsource that then.
All stored personal information needs to be PCI compliant.
I do security by not having things I don't need, printing documents and deleting the data. It's not perfect by it self but it is something we could model in hardware quite well.
One-way tubes seems pretty easy.
For access one could give each employee a query quota and if they exceed it have someone else increase it temporary or permanently.
One could also make a dumb console that displays data on a screen, db tables, pdf files, images.
Could build some business logic in hardware. More often than not the need for access is triggered by something. If the customer calls you some of their information can be displayed. Accessing it in the days after that isn't dubious.
It takes a lot and makes things more complicated but in the end you do get nice small data sets to work with.
It all sounds like lots of additional IT work, and it is (I spend a lot of time in our company to try and improve). But it only seems like a hassle because we went for so long without doing it right.
There must be a way to let human dignity be the lowest common denominator for shareholder value…
Cite, please.
Perhaps regulators in diferent countries take different attitudes; in the UK, it's very soft-touch. Only the most egregious, repeated flouting of the regs attracts a penalty.
As far as I can see, the Irish regulator is even softer; you could be mistaken for thinking that the Irish regulator's job is to make sure that US tech companies don't move their server sheds away from Ireland.
If you’re found to be in breach of the GDPR, the severity of the breach as well as the amount of negligence or malevolence on your part is taken under consideration to decide on the fine. The prosecuting attorney also doesn’t have to actually fine you if it’s clear you put in effort and acted in good will.
For a concrete example, a startup usually isn’t required to provide a fully fledged data deletion policy, but if you cannot roughly outline how you intend to handle people’s requests to delete their data, that doesn’t look good. If you don’t even have some sort of privacy policy on your website, that looks worse.
Nobody can implement the GDPR 100%. But you can try to handle data responsibly, and if someone discovers you don’t and you try your best to fix the error (which is on your part, mind you), nothing draconian is going to happen.
And we’re still talking about basic respect towards your users or customers here, it’s not like someone asks something ridiculous of you.
Maybe not.
It's convenient to think that misaligned incentives [0] or insufficient motives [1] explain failures of infosec. These are popular explanations amongst tech people, because we want to believe infosec can work. Our jobs depend on it.
Now there are gargantuan fines, shelves of regulation, auditing and compliance, even jail time for executives. Has it fixed anything? No. If anything the landscape of breaches is accelerating. And things like Microsoft Recall, cloud "AI" services are only going to amplify it. Even if we had a "corporate death penalty" that simply shut down companies on their first breach, it would fix nothing. We'd just get fly-by-night tech companies with an average lifespan of 18 months.
What if the people who said "Data wants to be free" are right? What if data containment is impossible in principle?
Once we put aside wishful thinking, how can a technological society survive. It requires radical and brutal re-thinking of cybersecurity. How we define it. How we teach it. How we legislate it. How we address harms.
[0] Bob secures Alice's data while Alice pays the price for Bob's failure
[1] Many people don't care. Not everyone has a security mindset, not because they lack intrinsic self-respect but because they are unable to comprehend the harms.
What companies paid a big enough fine to have an unprofitable year? Which executives are sitting in prison?
These things only exist in theory, not practice.
I’ll give you endless reams of pointless box checking exercises in the name of auditing and compliance.
I've heard serious suggestions floated for a tax and contribution funded pentesting agency that helps companies without waiting for the first breach. But I think the scale of it all is just a bit much.
It's almost impossible for those of us who've grown up in the last 40 years of commercial computing to imagine.
But it's possible to radically decouple identity from function.
They just keep the eggheads around as pets.
It's said thrice, but when you remove the monetary greed, you have Mullvad VPN.
P.S.: Yes, I say monies specifically, because the people who use "monies" as job parlance has the most monetary greed from my experience.
mullvad.net was interesting to me because I could pay with Monero, meaning that they may actually have no data about me whatsoever except whatever is technically required for a VPN connection. Pretty cool company but it seems like the sort of model that would struggle in most countries with the amount of financial monitoring that tends to be in place.
Having had conversations with people on security and anti-fraud teams, many experts clearly share this view.
That would probably be bad for tax receipts though, so it's more realistic that there's an upper bound on infosec related fines
Humans are very bad at security.
It's a small percentage of people hacking (in a malicious way) but the reach of the internet means we're all vulnerable.
Security for who. from whom and to what end?
I think many humans are bad at it. A smaller group, may be 10 percent, have the "security mindset".
For the ninety percent who use technology or run businesses it's a schlep and imposition. They just want to forget about it. And there are many psychological and cultural devices to help them ignore security.
Around 8 of remaining 10 percent are on what I see as the "dark side". They are guards for the castles, and primarily concerned with _helping_ technological abusers take advantage of the majority's weakness.
Same thing with tech. Most people only run backups of thier system after they lost data and felt pain at one point. I would guess most people have Maybe 3 password and just reuse them across evertlything on the internet. The only people who might be more security minded are the ones who do related stuff for a living or if they had a security incident happen to them. Nobody else cares.
Remove the ability to do online or offline credit card transactions without dedicated hardware for chip and pin, thus eliminating the value of stolen credit card numbers. Are you crazy we can’t do that customers would use a different credit card!
Change the incentives so credit card companies would be personally liable for any fraudulent transaction and suddenly everything changes.
They already are, which is why CC numbers are secured and all the other important info is not. This is exactly the point of the article.
If someone steals your CC and buys a bunch of stuff there’s 4 people who could be stuck with the bill. You, the merchant, Visa, and the bank who issues the card. Right now Visa is never paying though they still have a little hassle from such transactions. If you don’t notice you might get the bill and under special circumstances the bank might get stuck with it, but mostly it falls to the merchant. https://www.nerdwallet.com/article/credit-cards/merchants-vi...
However, if Visa/Master Card etc had some actual liability you bet they would be some real changes.
If what you mean is that we find ourselves unable to do perfect security, then that's clearly true but it's missing the point.
The point of the article is that we do better security for credit card numbers than we do for other information which is more sensitive to our customers. Why do we do better with these? The author's claim is that it is because of the incentives (although, working in the industry, I would say it is also because the credit card industry wrote policies mandating specific, detailed security practices).
I still agree that the punishment for these crimes is too soft, but even ramping it up to insane levels isn't going to make everything perfect.
Like, I'm in favor of personal liability for execs who willfully sacrifice everything and everyone else for their own increased profit as much as the next guy. But there are at least two major problems with your statement:
1) The kinds of infrastructural improvements needed to genuinely increase security are likely to take significant time and money to put in place—and the money, in many cases, will also mean more time. We're talking years in some cases, even if people are moving at the fastest pace they can while still being responsible.
2) Security is a genuinely hard problem. No matter how good your procedures, your hardware, and your software, humans still have to interact with the data, and humans will always be fallible. Social engineering, blackmail, revenge, and just plain carelessness will always put data at risk, even if the company as a whole is fully and wholeheartedly committed to security.
So are you going to put the heads of your local credit union in prison if someone in their IT department is disgruntled about not getting a promotion they think they're entitled to, and decides to stick it to the man by stealing the DB of social security numbers and selling it on the dark web? (Or whatever other scenario you can think of)
Yes we can. (But we won't.)