Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
Yes I completely agree. In the local news there was focus on which company it was and that the password was 123456.
Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.
Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.
They way I see it, there needs to be enough slack in an organization and the timelines for major products for people to not do the bare minimum. When management pushes goal X, and pushes hard, everything else starts to decay, including security. People need enough time to do the things they know they should do, but don’t feel they have the time for. At least this is where I’ve seen a lot of issues arise.
The security audit recommended changing the password to 234567, but management rejected it because it would require retraining staff
Im not in tech but still in corporate. Our store went through 6 GMs in 5 years. The problem is actually the corporate, not the new guy every 8 months who is being brought on to save the day. I think they're going to replace him again next year without addressing any of the issues on the ground.
Massive reorganisation will only happen if companies with poor security record go out of business, while competent ones win market share.
Otherwise shareholders do not care, because they do not have skin in the game.
Same for government staff. Unless they are explicitly fired there are no consequences of abusing the trust of public.
"I dont understand why there is not massive reorganisations in systems when things go wrong"
Because massive reorganisations can easily lead to even more things going wrong. Also most people are lazy and phlegmatic by default.
Rome wasn’t built in a day, not did it fall in a day. In a capitalist society you can gauge overall direction and success of the society but how well the market and private enterprise is doing, and well not merely in context of maximising shareholder value but as a fundamental part of the social fabric.
> I dont understand why there is not massive reorganisations in systems
This would just replace one insecure system with another.
It is time to recognise there's no such thing as a secure connected computer. And thanks to "AI" there's no such thing even as a significant defence lead over attackers.
A major problem we have is that computer programming is not engineering as people like to say. An engineering discipline VALUES redundancy and is always designing for safety. Programming likes to think of itself as math, and deliberately choses less redundancy for the sake of convenience and speed. The classical example is how operating systems are written with languages that allow an index to be out of bounds. We now have systems that are glued together using bubble gum pretending to be safe, when they fail in the most horrible way when one of the links break.
[dead]
Yeah that is a pretty weird opinion. Who cares about if he gets fired. He should be charged with criminal negligence and face prison time. Everyone is responsible for their own actions and its always possible to quit.
There's a very "child-like" (not in a good way) form of responsibility that everyone seems to lean into as they climb up - very intent-based.
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.