However, the law needs to reflect that if people are to actually take the suggestions seriously.
However, the law needs to reflect that if people are to actually take the suggestions seriously.
There’s no such thing as a secure system that’s usable. You can asymptomatically approach it giving infinite money, in the same way you can approach physical security (“if it were really important to you, you would’ve cloned Fort Knox, so I guess you don’t care”) or even the speed of light. But even Fort Knox is vulnerable to a highly determined invading army.
Getting compromised doesn’t inherently mean you made mistakes.
I entirely agree, but I think the reason you see such upset posts is that they are thinking of situations where EGREGIOUS mistakes were made and no liability was found.
It just rubs me the wrong way, like people who say goofy things like "all CEOs suck". They're picturing [insert your least favorite CEO here], but probably don't know, or temporarily forget, that the local bodega's owner very well might be the CEO of an S-corp that operates their little store for liability purposes.
Central control over everything gives you central way to shoot yourself in the foot. Duh. Don't be a control freak company maybe, or if you are, have 2FA on your admin's accounts.
"Nation state" my ass.
They also demonstrated that one rogue admin could have deleted the entire company in like one evening, too, if he felt bad enough.
Well, they also relied on this company to protect them, so...
https://www.bleepingcomputer.com/news/security/microsoft-ent...
And what is the limit on that, because the only actually-secured system is one that is not connected to anything or accessed by anyone.
Look, I agree that people are shit and the only person you can trust is one you've killed yourself, but that's not really a workable solution.