Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Although he miscalculated the cost here, the general point is somewhat valid I think. There's always going to be a trade-off between security and convenience / productivity / revenue / values / etc. And it's a good thing to think about that trade-off, because not thinking about the trade-off justifies things like mandatory strip searches of everyone boarding a plane (because terrorism!).

The bigger issue (which I think you're getting at) is whether this trade-off accurately accounts for externalities. Even if a security vulnerability only costs Sony $1 million, it could cost their customers, credit card companies, and any number of third parties a lot more than that.



An IT exec at a Fortune 100 company once described it as, "With 25K, someone can get into our network. We just need to make than # higher than most of the other companies out there. We can never be 100% sure as long as it's real people involved."


That sounds like the infosec version of "You don't need to outrun the bear, only outrun another person."

Might be a valid strategy if hackers only had the skills, motivations, and attention span of a grizzly bear.


That logic is presuming the attackers are randomly trolling, and that your company is not doing anything to attract a specific vendetta.

If the company is a "good citizen", then an approach like that may be justifiable. If you are BP, maybe not so much...


It also assume that the hacker won't just go after company A and company B


It's a valid point. I think it assumes that there's a time component involved too. The company did seem fairly on it's game on the time, and not one to flaunt controversy. But most hacks never get made public either.


One problem with that is that the hackers that you really need to worry about are ones who are coming after you: competitors trying to steal IP, business rivals investigating your deals and so on. These high profile attacks like the Sony attack are embarrassing, but the real business damage is probably done in other attacks that no one ever hears about.


The civil legal system is supposed to be the correct way for an injured party to recover losses from the party causing the injury. Sadly, this doesn't always work as effectively as it should. Probably because lawyers.


> The civil legal system is supposed to be the correct way for an injured party to recover losses from the party causing the injury. Sadly, this doesn't always work as effectively as it should. Probably because lawyers.

Even if you assume away any problems caused through either ill intent or simple not being perfectly omniscient by lawyers, judges, and jurors (all of whom can cause failures in the civil legal system), the impossibility of that system being a complete mechanism for recompense lies, among other places, in the fact that it is possible for the liable party to have caused harms to the injured party that the liable party is not capable of compensating. The harms a person is capable of doing are not limited by their capacity to pay -- someone with no assets can do an injury causing millions of dollars of property damage.


It's kind of unfair to target lawyers in cases like this. The real problem is combination of a patchwork legal system and powerful people's willingness to exploit it for personal gain.

Lawyers are just the _means_ by which those people exploit the system. They're also the means by which people who are wronged can get justice, so they're exploitation agnostic.


They're not agnostic -- they tie the probability of proper representation directly to capital capacity.


Right. Which, in the case of a massive data breach, would tend to cause them to line up behind the potential plaintiffs, not the defendant. In reality, in cases like this, both sides will have top notch representation.

(The problem, of course, is that there are cases where the stakes are non-monetary, or the plaintiff places a much greater value on a relatively small amount of money than a lawyer would...but I don't think that's really what we're talking about here.)


Also because companies try to remove all liability of their own when you sign the contract with them. Didn't both Sony and Microsoft update their EULAs so that you can't sue them - like at all? Sure, stuff like this may not hold in Court. But it may. Or at least it makes it extremely difficult to have someone sue them.


They can't get their duty to employees signed away that easily.


"accounting for externalities" is not the strong hand of capitalistic endeavors resp. "modern" business economics and this only changes very slowly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: