Ask HN: Why are there so many security breaches?

4 points by firstSpeaker ↗ HN
Is there any common reason behind the breaches? Is it the technology that is not mature enough or is it the cost cutting that results in breaches? Is it more about people behaviour or corporate decisions?

10 comments

[ 4.7 ms ] story [ 45.7 ms ] thread
The good guys (defenders) have to be right 100% of the time, the bad guys (attackers) only have to be right once.

This is the crux of the entire information security industry.

Yes, there are common reasons -- poor security practices resulting from a lack of empathy, a lack of a profit motive and a very low risk of any tangible consequences.

> Is it more about people behaviour or corporate decisions?

Yes. A small number of people directly decide what corporations do. A corporation's activity is usually carried out by a larger number of people, who have some, less direct, control over the corporate decision making. Orders of magnitude more people are affected by those decisions and have extremely limited and indirect means of influencing them.

The goals and motivations of capital will never be truly aligned with that of the individual/people/society.

Less bankers. Tax capital.

Neither governments nor the market adequately punish data breaches, so why expend resources in proactively preventing them when you can just let them happen and pay the (very unlikely) penalty which will be much lower than the cost of proper security?
It's maybe necessary to point out the fairly (?) obvious, namely that there can be no 100% secure system. A key can always get stolen or be replaced with a sufficiently similar one, and each door and lock has failure modes. That we nowadays believe digital systems are superior to brick-and-mortar, cash, personal interactions and actual signatures on physical paper—all of which can be robbed, stolen, staged, or spoofed—is largely down to our excitement about the perceived utility of doing things the digital way. But where previously a given interaction was only open to say thousands of customers per day (visiting the location of a shop), that same firm's web shop is now readily accessibly 24/7 to billions of actors who don't even have to be humans any more. I'd also venture that a fair number of bad guys only do it the cyber way because that might increase their chances to get something while decreasing their risk of getting caught.

For a transaction I had recently to install an ID app that then wanted to take photos of my face and my ID card. I had no recourse to another method nor can I know where and how these data will be stored. This data, collected in the name of increased security and trust, has now become part of the global data trove, making it a little bit more attractive to commit online crimes. Therefore, the party that forced me to undergo the procedure has, by their action, made the world at large and online transactions in particular a little less secure and trustworthy.

Absolutely. I think the party that needed to ID your face should take full responsibility if the data ever gets compromised. Perhaps they have a workflow where this data will be completely removed, but I somehow doubt it.
I also had the impression that they do not store some of the data verbatim but make a hopefully non-reversible fingerprint of it. But even so it's icky, and we have seen in the past that big players with all the money and IT expertise in the world got hacked and robbed. As it stands now, it's like a shootout. The party that forced me to undergo this procedure has hired the services of a third partner that I do not know and whose procedures, standards, and personnel I cannot audit. Should there arise legal issues the burden of a lawsuit or somesuch will weigh much heavier on my shoulders than on the other parties', who I assume have plenty of means to just pay for any lawyer and legal assistance they deem appropriate. Handing over very personal and valuable data in exchange for a promise, then hoping for the best and keeping fingers crossed is all of my part in this.
Good security and good security people cost money but don't generate any visible revenue. So if you care about your balance sheet, they make you look bad.

Optimism bias is also a thing. People assume bad things won't happen to them. (This is a psychological phenomenon not just an IT thing). So if you're an exec, you could advocate for spending the money or you could just pocket your bonus for cutting costs and go "pfft nothing is going to happen".

And there's the old "if it's cheaper to deal with breaches if they happen than to pay security staff most places are just going to assume nothing bad will happen and deal with the cost if it ever comes up".

> but don't generate any visible revenue.

This is the crux of the issue. Organizations have no incentive to invest in good security because they don't see any negative ROI in the now. It's amazing just how much they invest after the fact of a breach. They have to assume they will be breached at some point and have all the necessary operational security in place when they do get breached to limit the blast radius.

Opsec is usually an infosec term, but businesses do opsec all the time to protect assets and inventories, only it's not called opsec, just 'standard practice', or a 'business plan' or other terms, but really it's opsec under the hood. Also, opsec is not new, it's something long practiced by organizations and companies across the world.