Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Science and Technology
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
Reply Start New Thread
 
Old 11-07-2014, 08:10 PM
 
7,530 posts, read 11,363,895 times
Reputation: 3653

Advertisements

Quote:
Originally Posted by harry chickpea View Post

There are solutions, but they can be wildly expensive. The Russians went back to typewriters, stores that never computerized are unhackable...
That's related to one of the things I've been thinking about. Have we become overly high tech with too many things? I don't remember hearing about hacking in 1995.
Reply With Quote Quick reply to this message

 
Old 11-08-2014, 03:44 AM
 
9,689 posts, read 10,015,913 times
Reputation: 1927
Encryption service ...If you do not use it then you can get robbed or privacy can be taken and other people can be robbed
Reply With Quote Quick reply to this message
 
Old 11-08-2014, 08:04 AM
 
Location: North America
14,204 posts, read 12,279,947 times
Reputation: 5565
Quote:
Originally Posted by Motion View Post

There are solutions but they require a good IT team and more money than the average company is willing to spend in software and hardware. I also wonder how often these are really the work of hackers rather than internal employees simply selling off the data. It seems to me that I would rather craft a story about the former happening than the latter.
Reply With Quote Quick reply to this message
 
Old 11-09-2014, 11:50 AM
 
Location: The DMV
6,590 posts, read 11,286,252 times
Reputation: 8653
Quote:
Originally Posted by swagger View Post
You just proved my point. The failures are typically human, not a failure in their processes or policies.

A company with thousands or tens of thousands of employees can't guarantee that each and every one of those people will have the security of your personal data high on their priority list. It's not reasonable. What they can do is develop policies and procedures that reduce the risk of exposure as much as is practically possible. And honestly, what more can you ask them to do? You're a techie guy - what solution do you have that guarantees to eliminate the hacking of all computer networks?
And therein lies the issue. There are no guarantees in life.

But one of the biggest issues today with regards to information security is in the lack of security roles within leadership. I've been in InfoSec for over 15 years, and it's only within the last 7 or so years that you've started to see a change. I believe it was recently reported that both JPMorgan and Target did not have anyone in a CSO/CISO role. So it's no surprise that perhaps some of the security needs were probably overlooked. They didn't have anyone responsible for them.

And for most organization that may have a CISO or Security Director, they probably report up the IT chain. Which can be a conflict of interest. And I still see some companies where the IT head actually reports to the bean counter (CFO).

Again, this is slowly changing. But until you have leadership that can commit solely to risk/security, these breaches will continue to be normal occurrences.
Reply With Quote Quick reply to this message
 
Old 11-09-2014, 02:00 PM
 
23,597 posts, read 70,412,676 times
Reputation: 49258
Well said, macroy. Turf wars in the boardroom are constant in business. Beancounters and COOs will fight tooth and nail to avoid losing ground and influence. Only when a security director reports ONLY to the board will they have the clout to plug holes.
Reply With Quote Quick reply to this message
 
Old 11-10-2014, 09:19 AM
i7pXFLbhE3gq
 
n/a posts
Quote:
Originally Posted by NHDave View Post
And many companies take the stance of, we'll worry about it if it happens. They fail to do proper auditing or evaluation, fail to encrypt critical data, fail to keep servers updated/secured. People don't learn from other peoples mistakes. There are plenty more breaches to come.

The apology statements that always come after a breach claiming that our privacy and data security are of the utmost importance to them are nothing but a joke.
Pretty much this.

Home Depot failed to take basic security measures for years. They even put a guy in charge who, after being fired by his former employer, sabotaged their network. He's now in jail for that stunt. He also once offered up this little gem:

"I love to write and distribute Viruses. " - Home Depot's former senior IT security architect

Home Depot ignored security warnings for years, employees say | Ars Technica

Last edited by i7pXFLbhE3gq; 11-10-2014 at 09:27 AM..
Reply With Quote Quick reply to this message
 
Old 11-10-2014, 11:20 AM
 
10,926 posts, read 21,994,915 times
Reputation: 10569
Quote:
Originally Posted by JasonF View Post
Pretty much this.

Home Depot failed to take basic security measures for years. They even put a guy in charge who, after being fired by his former employer, sabotaged their network. He's now in jail for that stunt. He also once offered up this little gem:

"I love to write and distribute Viruses. " - Home Depot's former senior IT security architect

Home Depot ignored security warnings for years, employees say | Ars Technica
Yup, you can teLL HD was very concerned with our data security
Reply With Quote Quick reply to this message
 
Old 11-12-2014, 12:49 PM
 
3,695 posts, read 11,371,813 times
Reputation: 2651
I don't think that it's that hard, frankly. Apple Pay's model in which the merchant sees a specific transaction token rather than a general credit card number is a great solution. The merchant never, ever sees the credit card number and that number is never transmitted.
Reply With Quote Quick reply to this message
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


Reply
Please update this thread with any new information or opinions. This open thread is still read by thousands of people, so we encourage all additional points of view.

Quick Reply
Message:


Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Science and Technology

All times are GMT -6. The time now is 11:16 PM.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top