Although he miscalculated the cost here, the general point is somewhat valid I think. There's always going to be a trade-off between security and convenience / productivity / revenue / values / etc. And it's a good thing to think about that trade-off, because not thinking about the trade-off justifies things like mandatory strip searches of everyone boarding a plane (because terrorism!).
The bigger issue (which I think you're getting at) is whether this trade-off accurately accounts for externalities. Even if a security vulnerability only costs Sony $1 million, it could cost their customers, credit card companies, and any number of third parties a lot more than that.
An IT exec at a Fortune 100 company once described it as, "With 25K, someone can get into our network. We just need to make than # higher than most of the other companies out there. We can never be 100% sure as long as it's real people involved."
It's a valid point. I think it assumes that there's a time component involved too. The company did seem fairly on it's game on the time, and not one to flaunt controversy. But most hacks never get made public either.
One problem with that is that the hackers that you really need to worry about are ones who are coming after you: competitors trying to steal IP, business rivals investigating your deals and so on. These high profile attacks like the Sony attack are embarrassing, but the real business damage is probably done in other attacks that no one ever hears about.
The civil legal system is supposed to be the correct way for an injured party to recover losses from the party causing the injury. Sadly, this doesn't always work as effectively as it should. Probably because lawyers.
> The civil legal system is supposed to be the correct way for an injured party to recover losses from the party causing the injury. Sadly, this doesn't always work as effectively as it should. Probably because lawyers.
Even if you assume away any problems caused through either ill intent or simple not being perfectly omniscient by lawyers, judges, and jurors (all of whom can cause failures in the civil legal system), the impossibility of that system being a complete mechanism for recompense lies, among other places, in the fact that it is possible for the liable party to have caused harms to the injured party that the liable party is not capable of compensating. The harms a person is capable of doing are not limited by their capacity to pay -- someone with no assets can do an injury causing millions of dollars of property damage.
It's kind of unfair to target lawyers in cases like this. The real problem is combination of a patchwork legal system and powerful people's willingness to exploit it for personal gain.
Lawyers are just the _means_ by which those people exploit the system. They're also the means by which people who are wronged can get justice, so they're exploitation agnostic.
Right. Which, in the case of a massive data breach, would tend to cause them to line up behind the potential plaintiffs, not the defendant. In reality, in cases like this, both sides will have top notch representation.
(The problem, of course, is that there are cases where the stakes are non-monetary, or the plaintiff places a much greater value on a relatively small amount of money than a lawyer would...but I don't think that's really what we're talking about here.)
Also because companies try to remove all liability of their own when you sign the contract with them. Didn't both Sony and Microsoft update their EULAs so that you can't sue them - like at all? Sure, stuff like this may not hold in Court. But it may. Or at least it makes it extremely difficult to have someone sue them.
The bigger issue (which I think you're getting at) is whether this trade-off accurately accounts for externalities. Even if a security vulnerability only costs Sony $1 million, it could cost their customers, credit card companies, and any number of third parties a lot more than that.