They do take security seriously
lvh.io
lvh.io
That's a grossly uncalled for rewriting of the reality involved.
The victims are NOT the company whose servers are compromised. The victims are the customers of the company, whose data has been lost to the wilds.
Edit:
> It is far more probable that all of the companies cited in the article have expended massive efforts to protect themselves
Another misunderstanding of reality. I've worked with and in quite a few companies of tiny and impressively large size, and in all instances so far security has been a non-topic, or at best a bullet point on a slide. In all cases so far has it been utterly trivial for literally anyone inside the company, and mildly trivial for people outside the company to create data loss scenarious of disasterous scale for many many customers.
Maybe he has worked exclusively with companies who have crack security teams and never even thought of using md5 to hash passwords. In my, and many other's, experience, such companies are as rare as unicorns though.
If I am running a company or even just working there, and someone attacks my servers, even if Customer ABC's and Customer XYZ's data is what they want, as far as I am concerned, it's my system that is under attack.
Customers ABC and XYZ are under attack as well. We all are.
After keeping the breach(es) a secret for at least months, Chase kept strong with its spin on the topic. It is clear that Chase does not consider the breaches too important to its business. As far as Chase was concerned, their perspective is that they dodged a bullet. If there was any indication that account balances were fudged, I doubt Chase could keep nearly as calm.
My tired point is that for many companies, they make a distinction between "them" getting breached vs their customers' data getting breached. How can we believe that Adobe does not know the best practices to store passwords?
Also from the article:
> These commentators have presumably not been the victims of a breach
> themselves. I have trouble swallowing that anyone who's been through the
> terrifying experience of being breached, seeing a breach up close or
> even just witnessing a hairy situation being defused could air those thoughts.
I do emergency incident response for companies that get breached, and this is off the mark. Without going into detail, an ounce of prevention is worth a pound of cure.It is entirely standard operating procedure in the startup industry to play fast and loose with customer data, ignore best practices, get breached, make a blog post about how "we take security seriously", fix one or two things, and continue like nothing happened. It's the users that suffer, not the startups that get breached.
It's bullshit, and Troy is precisely on the mark for calling it out.
Aye.
https://paragonie.com/white-paper/2015-why-invest-applicatio...
Is it realistic to expect a health company to have prevented a breach if that breach is a consequence of an Exchange 0-day? The topic of the article is that the breaches have gone on for a significant fraction of a year. If that is the case, that there are intruders waltzing in your network, it is hardly appropriate to say that you take security seriously.
Allow me to illustrate. It's not physically difficult to get murdered, but you don't have to walk around in a suit of armor or tank in 2015, because you live under a code of laws. So safety/security is a public good.
By the logic that the operator of the servers that have been illegally attacked aren't the victims, we can say that public safety is the real victim: people who aren't even involved are the real victims, because there are more of them, and they all have to be more careful as a result.
But that reasoning is kind of silly. The victim of the crime is the operator of the server that was illegally accessed and compromised, and if these criminals had something better and more productive to do with their time it wouldn't happen. It's up to laws to make that be the status quo.
It's great when technology can protect us - but let's admit it, it's like going shopping in a tank: a technological solution to a social problem. You can't always do it. (Technological solutions don't always exist.)
That they have to choose passwords of string complexity, that they have to use different passwords for EVERY single thing where a password is used, and optimally even that they use a different login for thing requiring one. That they be very careful about what exact data they share with any given service. etc. etc.
You may have intended to be snarky in your response, but you have unintentionally hit the nail on the head.
I also don't mean to say that that doesn't mean the company didn't mess something up. However, that's a completely different story: there are worlds between "made fatal mistake" and "doesn't care the tiniest bit".
These are companies failing to enact the basic security practices taught in introductory college courses. They're companies disclosing a breach six months after it happens, just before (or after) independent researches make it public.
If a few of these companies have used best practices and been caught with new exploits, they deserve to be given kinder news stories than the usual. In practice, though, the story is almost always one of neglecting even basic security.
Yes, but the article points out two complications:
1. We only know about those cases where the company has publicly disclosed their breach. There may be lots of victims, and just caring about the publicly-known ones seems misplaced.
2. In many cases, the data has not been lost. "Servers compromised, encrypted data stolen, decrypted keys not stolen" is generally more-or-less fine under a threat model. Victims of the LastPass attack last month are much less at risk than, say, victims of the 2013 Adobe attack.
It's important that we build a world in which prospective password-managing companies are incentivized to act like LastPass and not like Adobe, and I'm worried that LastPass is only acting like it is because they're good people (leaving room for a smooth-talking amoral competitor to undercut them). My general impression is that the companies that don't care about security are being very rational about it: getting it right is expensive, you're at risk either way, and the PR blowback is not well-correlated with how good your security design was. So you might as well not care, and as long as nobody cares, you can just write "industry-standard security measures" in your blog post once you're hacked.
On the other hand, I can think of a number of companies that have a track record of making high quality products, and none of them regularly feel the need to issue press releases touting their commitment to quality.
Just saying "We take security seriously" is like saying (to quote Chris Rock) "I take CARE of my kids!" What do you want, a cookie? That's what you're supposed to do.
Then how do users ask for anything better than the status quo?
> How can the security industry build deep relationships with clients when we publicly ridicule them when the inevitable happens?
Simple: Call out the competitors of the clients you seek. There, now it's positive PR for your clients and security researchers aren't practicing self-censorship. Win-win.
They didn't care about security at all. That's the assumption. And it seems I'm not the only one to think that, because that's how thing are generally.
Although I don't agree with all that is said in the article. I find that it makes a nuanced and well structured point.
Depending on what the security industry wants to achieve, they can either ridicule (punish) or ignore (reward) companies that at least publicize they've been breached. Keeping in mind that companies have a certain tendency to work short-term angles over longer-term alternatives. I think the carrot is more likely to achieve better security than the stick.
But that's just my 2c.
I think public ridicule is necessary as basically the only way users have to encourage security. Users are being harmed by a company penny pinching on security and virtually never receive any compensation.
I've no pity for devs that end up getting ruined because they didn't know what to do. It's like going too fast on a freeway you don't normally take, getting pulled over and trying to explain that you didn't know. You knew better. Ignorance is no excuse.
Ridicule is absolutely an effective response to companies who have put MILLIONS, literally MILLIONS of people in fiscal and possibly even physical danger. There's absolutely no room for error when it comes to safety for the users, and a tweet saying "Oh yeah, well uh we take opsec real real serious" doesn't cut it.
Of course they take security seriously, I mean obviously. But the point of the article that this article is responding too is that it doesn't matter if apologize after something that could've been prevented, it's too late.