Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security" engineer(I know of a few areas where I'd like to shore up but they never come up on security audits, hmmm), this is often sufficient. Besides, don't you figure Target, Home Depo, EA, and Sony had dedicated security people?
Again, this is not arguing against security guys.. It's just this post reads a bit like "Well, if they were only hiring people like me maybe this wouldn't have happened".
Only you can prevent forest fires. The aggregate knowledge and concern for security needs to increase. A lot of these security auditors(but not all!) are just running automated tools and generating automated reports. They don't understand your environment like you do. Even a dedicated security guy at a large company can't be everywhere and doesn't know everything(or even understand, say, hypervisor security). I was lucky enough to work with/for somebody that was very security concious and involved in the security scene... It changes your thinking. This thinking while staying pragmatic is the key IMHO. Just like the mantra "everyone is responsible for quality" I believe everyone should be responsible for security. If this isn't specific enough well.. Consider some of the hacks mentioned before. It is at the same time completely obvious to some people what went wrong in hindsight, but obviously not apparent to the implementers that it could go wrong at the time. A cultural shift in thinking and better education in security is the way forward IMHO.
A lot of these security auditors(but not all!) are just running automated tools and generating automated reports.
Woah... A professional security auditor actually knows what to look for and would be flexible enough to understand (and manipulate) what your software is doing. If you are paying someone to run a script, you're not getting your money's worth.
Even a dedicated security guy at a large company can't be everywhere and doesn't know everything(or even understand, say, hypervisor security).
True, that's why ideally you'd want a team of people on this, not just one security guy to carry the globe.
I agree though, security needs to be thought out from the beginning and throughout the development process. The later you catch something, the harder it is to fix. But you need a fair amount of experience as a developer to see security issues thoroughly (because you often need to understand the platforms you are building on, not just your domain). So if you don't have that knowledge you can either teach yourself or if you don't have the time, let someone else do it.
Having a thorough understanding of what you are actually doing does take care of most of that. I doubt that's where a startup's priorities are, sadly. For most, speed > solid code
"You can’t just hire a couple security engineers to shoulder this burden. You wouldn’t hire anyone to just “go deal with that scale issue” you have either."
Most startups that talk to me do hire somebody to "go deal with that scale issue." When they talk to me in particular, it seems like they want to hire somebody to "go deal with that security issue," too.
We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.
That said, any company collecting PII (or any type of data a customer believes is protected really) as part of their business has a duty of protecting that information.
Unfortunately, you can't trust joe sixpack to make safe and sound decisions as to whether they should sign up and give their contact/personal info to your new random app, let alone evaluate the level of your opsec practices.
Saying "we take the privacy of our customers very seriously" months after a breach and going back to business as usual is not enough, and I think this is true for both startups and big corporations.
One of the earlier comments said "Stop fucking ruining people's lives.", I think it pretty much sums it up even if it's probably a bit extreme.
The first step is to stop considering security as an afterthought when you write any piece of code.
This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.
Your view doesn't account for the fact that in computer security, offense overwhelmingly beats defense. Target. Sony. Home Depot. Nordstrom. Those are the ones you hear about, but what's scary are the number of company and government breaches that aren't made public. The cost of a zero-day is in the low to mid six figures.[1] If you are a juicy enough target, you will get hacked.
Obviously, this doesn't mean one should disregard security concerns. It's important to engage in good practices, to cultivate a combination of paranoia and attention to detail, to scrutinize suspicious behavior. But even if you do all of these things, modern computer systems have tons of surface area outside of your control. These days, it's unrealistic to demand perfect security from anyone, let alone small businesses.
Instead of being so uncompromising, I think it's better to ask businesses to explain their security policies and practices. Are administrators required to use multi-factor auth? Are backups encrypted, and if so, how? How are passwords hashed? Is data encrypted in transmission, and if so, how? Are server logs shipped to prevent tampering? Answering these questions (and others like them) can give security-conscious customers an idea of the business's expertise, and allow people to use products (or not) accordingly.
No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had enough of perfectionists like you keeping people from making stuff.
Yeah, and fuck food safety regulations, because I'm just some schmuck who wants to operate a restaurant but can't be bothered to learn about how to do it properly so everybody who doesn't want to be poisoned shouldn't be such a bitch who'd prefer a steak without a side of e coli, right? And let's abolish drivers licenses too while we're at at, because anyone who wants to have a bare minimum of driving skill from other road users should just go live in Somalia, right?
Well actually, if you think it's OK to expose your user's data because you don't know what you're doing but think you deserve a piece of the startup gold rush pie anyway, it's you who should go live in Somalia and see what becomes of a 'society' of people who just do something with no oversight, skill of knowledge. If the choice is between 'doing it poorly' and 'nothing at all', then you should do 'nothing at all' because your actions affect other people. Basically you say 'screw my users, I can't be bothered to learn things properly but I want money anyway!'. Well, fuck you, you are the cause of all these problems, and you deserve everything that comes to you.
That's not perfectionism. His comment is an emotional simplification of a complex problem without any consideration of side effects. This is just like being "tough on crime" rhetoric of some politicians.
nothing, otherwise you put yourself at a disadvantage against other market players (at least in US).
US has no reasonable industry regulation, its more of a laughable industry written guidelines if anything. There are no consequences, no serious penalties for harming public. Whats more public itself is too clueless to care and incentivize proper behaviour. Only HUGE events are capable of changing (exxon valdez) perception and forcing real regulation.
Again, this is not arguing against security guys.. It's just this post reads a bit like "Well, if they were only hiring people like me maybe this wouldn't have happened".