(no title)
VieElm
|
10 years ago
I don't understand the criticism, what are they supposed to say instead? When an attacked company says "we take security seriously" it's probably a statement made by someone in the company who really does care about it and is probably pretty upset about the whole ordeal and wants to fix it. This whole attitude about corporations always being these evil lifeless monoliths who don't care about anything and are just saying whatever they need to stands in contrast with any place I've ever worked. Some of these companies are staffed by people who do care and want to do the right thing and I don't understand what the OP thinks they should say instead.
ploxiln|10 years ago
Security is always the very last thing they care about, until there's a huge very costly breach. Then they care for 2 months, and I get to actually work on the security stuff, and get other developers to cooperate, and clean up the known messes left all over in the typical mad dash of feature addition and replacement. Then it's all forgotten about again.
They should say "we suck, we focused 100% on features and market share, we know now what's important", and they should get security right. It does kinda suck that the market often rewards companies that prioritize all else above security, and I wish such companies all the damage a breach can cause. Otherwise, there's no reason to not suck at security.
They should just be honest: "This is what happens when you make a product people love. It's insecure and data is lost and service is interrupted. But you all love it so thanks :)". People should not be under the illusion that their favored products and services are secure. They should know they love insecure shit.
ProAm|10 years ago
hippo8|10 years ago
What most people don't realise when it comes to computer security is, the foundation on which our modern systems are built never anticipated this much growth.
I think I am happy with companies that care enough to come forward and admit their mistakes. IT security is hard, very very hard.
siliconc0w|10 years ago
You really need a good security guy who can be the bad guy and stop projects in their tracks when it's clear there are security issues. Because asking the same people who are accountable for shipping to stop the presses to fix even the obvious shit you already know about is a challenge - much less investing resources in 'shoring up' against attacks you don't anticipate.
nissehulth|10 years ago
If there are people that truly do care, they should stand up in the early process and make sure enough budget is allocated.
ams6110|10 years ago
ryandrake|10 years ago
elchief|10 years ago