‘Just make the encryption secure and so we can read it’
‘Just check everyone’s id but make it totally secure’
‘Just make the encryption secure and so we can read it’
‘Just check everyone’s id but make it totally secure’
I can hear the defense now: "Oh, yeah, you blame the honest, good, handsome people trying their best to protect you and you let the hackers off scot-free! We must make sure that hackers don't have access to the tools that aid them to commit these crimes, like books and computers. Anyone could be a hacker."
[1] A credit monitoring service that will give the institution that "free 12 months" at a vastly reduced bulk rate because it knows that in order to sign up for free credit monitoring you actually sign up, with a card, for their top tier product (which might otherwise be $50+ a month) on what is effectively a 12 month trial after which they switch you over to a paid subscription (hell, there may even be commissions paid to the institution for anyone who neglects to cancel quickly enough). The incentives are so perverse.
The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know.
I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?
I've also seen cases where it's like, maybe we shouldn't share S3 Root Creds or put it on the VPC so we can monitor outgoing traffic but too many applications would need to be redeployed for that so skip it. Those 2 year old tickets were still sitting in the backlog when I left.
If we ever get report, it's extremely likely going to be massive failure and only way to change this is fines for company that are bankrupting.
EDIT: Oh yea, SOC2 needs to go away. It's security theater that's just giving cover to companies.