8 ms·
Government regulation? They can't keep themselves secure. There was just a post here a couple of days ago saying how vulnerable the DOD's systems are. How are t
by GreenToad5 8y ago
Government regulation? They can't keep themselves secure. There was just a post here a couple of days ago saying how vulnerable the DOD's systems are. How are they going to police others when they can't police themselves?
I work in the banking industry where security IS regulated (by the FDIC). We have government auditors come and review our technology once a year. These guys don't know what the hell they are doing. We have had blatant security problems (now addressed) that they couldn't see right in front of their nose. Community banks have terrible security. Larger ones are better, but still rife with problems.
I fail to see how government regulation and intervention has helped in my industry, or how it would help in any. If by regulations, you mean that we would get fined if some data got compromised, that already happens through negligence lawsuits. It is not an effective motivator though.
In my experience, the threat/worry of bad publicity is actually the best motivator in a company getting their security up to par.
- deleted 8y ago[deleted]
- kartan 8y ago> In my experience, the threat/worry of bad publicity is actually the best motivator in a company getting their security up to par. If that were just true Facebook will not exist. > I work in the banking industry where security IS regulated. We have auditors come and review our technology once a year. These guys don't know what the hell they are doing. Regulations do not make problems disappear but make the situation better. If you vote for politicians that want to improve it, instead of politicians that are paid by lobbyists to free companies of their responsibilities.
- roms 8y ago> Regulations do not make problems disappear but make the situation better. I also work in banking (major financial hub in Europe). Regulation is the bane of security and data management because it adds several layers of complexity on top of already complex processes. It leads to people performing repetitive tasks to comply with regulation, leaving no time for in-depth analyses, process reviews and enhancements, and the clean-up of sensitive data. You provide a baseless assertion shoehorned with a comparison to lobbyists nobody ever brought up. I can't prove a negative but you sure didn't prove your positive.
- chazhaz 8y agoA big problem is that regulation tends to be pretty porous. Rather than curbing bad behaviour, it just adds, as you say, several layers of complexity on top of the bad behaviour. And the task of handling that extra complexity ends up on the desks of the working grunts keeping the system churning. Like with GDPR, the regulation was to give people control of their data and make privacy by default an available option. But it's just given users more hoops to jump through before scooping up a user's data anyway. Regulations tend to be a bit of a nudge in the right direction, but play out as something systems have to work against to keep things running the way they were before.
- candiodari 8y agoA second huge problem is that governments ... don't know how to do security. So they just mandate some random measures. And then the problem is that people follow their measures ... and see this as absolving them of further responsibility. In many cases in the financial world that isn't just laziness: that's actually how the law works. So much of the regulation burden doesn't just force the whole market into large companies, it actually opens up and legally mandates not security, but security holes.
- lambdadmitry 8y agoCan you please provide a single case of high profile security breach that was caused solely by regulation? That must be easy if what you say about regulation opening holes is true.
- saiya-jin 8y agowell, 2 points: - you create a throwaway account just to moan how regulations complicate life for banks - you can't stand up to your own opinions? Can't expect much respect for such a behavior - I work in banking too, and lets be honest - banks brought all the crap coming their way themselves. Not every single one of them, not every single employee, but greed and utter ignorance was rampant, and still is present to certain extent. Moral and bonuses don't work well together. Plenty of high ranking managers wouldn't care if the world would burn to the ground as long as they are OK (unfortunately this is valid across all businesses, you can't expect normal nice sane people up there, even if they would somehow climb up there, they wouldn't survive long in company of sociopaths). But banking sector has terrifying power on world economy as seen in 2008, so tight oversight is necessary, like it or not.
- matt4077 8y agoBanking seems to be doing pretty fine, actually. Can't remember any cases where customers lost money. So maybe they are doing something right. > the threat/worry of bad publicity Yeah , that hasn't worked for Exxon Valdez, nor for any of the recent data dump incidents.
- _puk 8y agoPresumably we're ignoring Identity Fraud when we say banking is doing pretty fine? Obligatory Mitchell and Webb "Identity Theft" link: https://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- amelius 8y agoBanks are doing security right because it is in their best interest. The average IT company however doesn't care much about leaks of customer data, except perhaps for the publicity effects.
- chewz 8y agoTo the contrary. Banking is scared shitless. Internet access to banking account is not a matter of if you lose money but when. The Underworld is now multibilion dollars business and is getting better at it's trade with every day. It is relatively safe and lucrative. Identity theft, SIM swap, SWIFT half a bilion dollars theft in Bangladesh, South Africa - Japan credit cards. Just to name a few. Remember that money at the end of the day is based on trust. If you cannot trust that the money on your account are safe. Or if your money is not liquid because banks have to manualy verify dubious transactions then your money are loosing value. 1 https://en.m.wikipedia.org/wiki/Bangladesh_Bank_robbery https://en.m.wikipedia.org/wiki/Bangladesh_Bank_robbery 2 https://www.bbc.com/news/world-asia-36357182 https://www.bbc.com/news/world-asia-36357182 3 http://fortune.com/2017/05/05/wire-transfer-fraud-emails/ http://fortune.com/2017/05/05/wire-transfer-fraud-emails/
- rossng 8y agoMy suggestion would just be to significantly ramp up the fines. No need to bother with pointless tickbox compliance audits and all that other stuff. Obviously you would also have to have some pretty strong rules around covering up security breaches - I would suggest explicitly making it a serious criminal offence. Hopefully the GDPR will have a positive effect here. If you suffer a security breach, you can expect to face severe financial penalties. I'm sure companies will figure out how to secure themselves surprisingly quickly after they see a few of their competitors get fined several hundred million euros.
- candiodari 8y agoIF we apply the same to political organisations leakage, then ok. Keep in mind that Congress, EU parliament, EU commission and I'm sure many others were all hacked in the past 2 years. Needless to say, they all see themselves as above this whole regulation thing. And of course, those penalties cannot come from the tax coffers. They need to be leveled against the pay of the politicians, because otherwise how could they ever work ? The EU parliament's websites are currently clearly in breach of the GPDR as well. Let's start there, shall we ? As long as this is their attitude, I feel like this is not an acceptable solution.
- sievebrain 8y agoYou are correct sir, however the EU commission believes it doesn't actually have to follow the gdpr at all! They were called out on their non compliant website shortly after the law activated and announced that for "legal reasons" they didn't have to follow it.
- gkya 8y agoI'm going to exploit this comment which is at the top of the thread and stands above another comment that argues against government regulation in software industry to tell you guys this: hopefully this industry will be regulated from top to bottom before too long. GDPR came, hopefully more will come, w.r.t. security, privacy, and even UX standards (e.g. all companies should be required to accomodate all sorts of disabled people, probably by allowing assistive tech in browser to work properly on their websites). You guys will not and want not to fix the status quo where shitty software is pushed onto us. You guys will not stop implementing unethical, "agressive" software. So someone should be watching over you, entrepreneurs and devs, and that someone is the government. Government regulation need not be perfect. But it needs be there. That means companies will be more incentivised to keep their shit together. Surely your bank would be doing worse if nobody was watching over. If more budget and worktime is devoted to such regulation, it will become better. I understand that no regulation is a strong political position in the US, but I call bullshit on it. I wouldn't bother writing as I'm mostly at the user side of things these days but I wanted to write this given most of you are devs here. It is not about some silly social network or an irrelevant SaaS anymore. The world runs on this, software is as important as medicine and food to our livelihood, and the software industry needs to be regulated like medicine or food industries are. Something simple like Twitter and Facebook affects lives of the masses. You'll have to get your... act together.
- beaconstudios 8y agoYour argument is that banks don't have the will to fix security issues. The parent was arguing that security is hard and that the government is not particularly competent at it so is not in a position to define raised standards. You're not even having the same conversation.
- cm2187 8y agoSome complex CPU or encryption bugs is what makes full security hard. But most security breaches are because of people doing stupid things. Unprotected public databases or s3 buckets, sql injections, plain text / easy to guess passwords, out of date software, etc. I am ready to bet that those alone constitute more than 90% of the breaches. And this is the result of mere amateurism. If tech people do not care about security or aren't competent enough to take even the most basic steps, regulation is absolutely the right response.
- hrktb 8y ago> Government regulation? They can't keep themselves secure Wouldn't this be akin to say "Criminal laws ? the cops can't even police themselves!". It can be true, and you'd still need a framework to define the wanted behaviour anyway. Enforcing the standard is a important and separate issue.
- leetcrew 8y ago> Wouldn't this be akin to say "Criminal laws ? the cops can't even police themselves!" yes it is. not too long ago there was a major issue with undercover cops in baltimore committing many of the serious crimes that they were supposed to be policing! [0] the commissioner (rightly imo) suspended undercover enforcement indefinitely. [0] https://www.washingtonpost.com/local/public-safety/plainclothes-policing-in-baltimore-is-over-says-commissioner/2017/03/08/f0b72110-0425-11e7-b1e9-a05d3c21f7cf_story.html https://www.washingtonpost.com/local/public-safety/plainclot...
- ganzuul 8y agoCriminal laws exist though, so you miss the mark in your objection.
- dkrich 8y agoThis is all true. Security is best implemented when it’s baked into an organization’s processes. The government barely has enough budget to pay for server space let alone invest heavily into dedicated security teams. Most work is handed off to outside private contractors but they are hamstrung by the same budget issues. Security concerns are almost certainly best handled by private industry except in rare cases like national security or the public markets. For example if Boeing becomes known for being easily hacked and flying unsafe planes, how long do you suppose they’ll be around? A company’s livelihood relies on the perception of being secure and they are well aware of this so the ones that want to succeed absolutely invest very heavily in security. A successful hack doesn’t mean companies don’t invest in security or that people don’t pay for it.
- pixl97 8y agoCompanies lived are on the line, I mean it is terrible that Equifax doesn't exist after losing all that customer data after being hacked... Wait
- mannykannot 8y ago> In my experience, the threat/worry of bad publicity is actually the best motivator in a company getting their security up to par. The banking industry got the regulation it has now because this did not work. If the situation is as bad as you describe, then apparently not even the threat of government regulation was sufficient motivation for banks to get their act together.
- candiodari 8y agoAnd as we noticed in 2000, 2008 and in the EU crises: Regulation does not work either. For 2 main reasons: * Regulations are stupid and do not catch all problems, which then causes those uncaught problems to become systemic and threaten not just the bank, but the entire country, because regulation often also forbids or discourages banks from checking other problems (or at the very least pushes an attitude of "if you check compliance with the regulations, security check done" * Governments cannot be trusted to carry out the regulations ("too big to fail")
- branksy 8y ago> They can't keep themselves secure... they can't police themselves? What does that have to do with it? Better laws on security will force the government to police itself better too. Simple example: a law requiring all passwords to be stored with unique salt and encryption of certain minimum strength. Or a law preventing IoT devices from functioning on a network when their password is still set to the default. How do you fail to see how simple actions such as these would help?
- trey-jones 8y agoBoth examples that you give are sound, and I would support regulations that enforced these basic security guidelines. The question is whether these are the types of regulations we would get. I expect there would be rather a lot of useless and silly regulations that do nothing but drive up costs.
- varrock 8y agoThis is not a rhetorical question, I'm just trying to better understand how this process would work. Who would be designing and brainstorming these laws in the government?
- trey-jones 8y agoI do not know the answer to this question. It seems reasonable that a "committee of experts" would be designated by the politicians for this purpose, but I don't feel confident that one could be sure of the expertise involved, or whose interests would be served.
- RegBarclay 8y ago>We have government auditors come and review our technology once a year. These guys don't know what the hell they are doing. We have had blatant security problems (now addressed) that they couldn't see right in front of their nose. I've seen the same issues in SarbOx audits. The auditors don't know beans about the underlying technologies. A lot of evidence requests take the form of screen captures showing x. Well... I can give you a screen capture showing you whatever you want whether it represents reality or not. Ultimately, with our without regulation, it comes down to people being honest professionals. Regulation is all for show.
- bliblah 8y ago>In my experience, the threat/worry of bad publicity is actually the best motivator in a company getting their security up to par. I think the Equifax debacle has shown otherwise. Big corps have too much Lobbying power and PR presence for public shame to make a lasting impression. Facebook is on the hot seat right now but that too will pass since legislators are fickle and myopic. Heck Google straight up shut down G+ because of "Security Concerns" and no one batted an eye.