logoalt Hacker News

mmsctoday at 3:42 PM4 repliesview on HN

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.


Replies

Nextgridtoday at 4:38 PM

The purpose of cybersecurity products and companies is not to sell security. It's to sell the illusion of security to (often incompetent) execs - which is perfectly fine because the market doesn't actually punish security breaches so an illusion is all that's needed. It is an insanely lucrative industry selling luxury-grade snake oil.

Actual cybersecurity isn't something you can just buy off-the-shelf and requires skill and making every single person in the org to give a shit about it, which is already hard to achieve, and even more so when you've tried for years to pay them as little as you can get away with.

show 2 replies
yoyohello13today at 4:10 PM

If crowdstrike is any indicator, expect Ivanti stock to go up now. Seems to be the mo for security companies. Fuck up, get paid.

show 1 reply
Nextgridtoday at 4:31 PM

> How they haven't been sued into bankruptcy is something I'll never understand.

Isn't most off-the-shelf software effectively always supplied without any kind of warranty? What grounds would the lawsuit have?

show 1 reply
waihtistoday at 3:46 PM

Well, next week there will be a similar vulnerability Fortinet and everyone will momentarily forget about Ivanti again :-)

show 1 reply