'We hacked the FBI:' Hackers say they have data on all FBI employees
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
'We hacked the FBI:' Hackers say they have data on all FBI employees
Unofficial Hacker News client; not affiliated with Y Combinator.
jacobgold · · focus · HN ↗
China hacked 22.1 million records of US government employees:
<a href="https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
coldpie · · focus · HN ↗
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
throw1790150052 · · focus · HN ↗
There is such thing but almost never a priority. In the corp I work leadership talks a lot about security but when comes to the incentives the road-map takes priority over the security. If you deliver fast you'll be promoted, if you're a paying attention to the security no-one will appreciate it and the manager will hate you for delaying delivery. Many managers I interact with see new features as the main value development teams should provide and security, reliability and other QoS as a waste to be minimised.
Another issue is that even if security will be a priority and managers will be on board (good lock changing the culture tough) we probably cannot build secure systems while keeping the insane level of complexity we have nowadays. Switching to simpler but secure system will require sacrifices in features/convenience.