If my security is an afterthought to you, then you don't deserve my business.
If my security is an afterthought to you, then you don't deserve my business.
Plus, I'm not sure where you possibly got billions in annual revenue? They're incredibly public about their statistics and business model. They take 5% of successfully raised projects. They report $842M successful dollars on the site, for a lifetime revenue of $42 million in the 5 years since they were founded.
Handling Other People's Money is the essential part of their business.
They didn't detect the intrusion.
The last one tends to concern me in these sorts of incidents.
In any case: if you're setting the bar for "handling transactions online" at "must be the first to detect any compromise", you're probably good with using Amazon and... hm, probably nobody else.
And, you know, outside of computer stuff where I send my money to NewEgg, I do by default prefer Amazon to all others.
(NewEgg has good prices, superb shipping of bare hard drives, the very best and informative reviews, and now a question and answer system, which sends email to people who've bought a product in case they can answer them. Or so I've found with a fan I recently bought, and helped two people, in one case whipping out my micrometer.)
For what it's worth: we don't generally recommend IDS deployments.
(That is not asked out of idle curiosity, and I've been told the worst intrusions hack the kernel so tripwire would likely be useless, but don't know if those are widespread.)
Tripwire is not a total waste of time, like a network IDS would be, but for most startups a minute spent setting up Tripwire is a minute that could be better spent on appsec.
Also with proper hardening you can prevent the kernel from being modified even by root. Things like FreeBSD securelevel that once enabled blocks writing to kernel memory and raw disk devices.
File integrity is also a pain in the ass. You have to keep a database of good file hashes and it can't be stored on the server (or the attacker modifies the known good hashes). Generally you also should not even have the file integrity software on the live server filesystem.
Similarly Network IDS has the flaw that you must have well defined profiles of "normal behavior" so it can identify abnormal behavior. The other option is signature-based but that would only detect known exploits.