Why the fuck was I breached?(whythefuckwasibreached.com)
whythefuckwasibreached.com
Why the fuck was I breached?
http://whythefuckwasibreached.com/
44 comments
> I love fun toys like this and would love an awesome list of them if anyone has one.
From the Bastard Operator From Hell series:
http://pages.cs.wisc.edu/~ballard/bofh/bofhserver.pl
https://meyerweb.com/feeds/excuse/
From the Bastard Operator From Hell series:
http://pages.cs.wisc.edu/~ballard/bofh/bofhserver.pl
https://meyerweb.com/feeds/excuse/
I can't tell if the random excuses are completely made up or come for actual breach incidents. If the latter, it would be interesting if the site actually gave an example, or linked to a story, where a company used a similar excuse or reported cause.
[deleted]
[deleted]
>>> But we have since upskilled our cafeteria staff, so it will never happen again.
I am not sure they are being entirely serious with their random excuse generator. I could not recommend use of this to corporate legal.
I am not sure they are being entirely serious with their random excuse generator. I could not recommend use of this to corporate legal.
I wish I could submit my own options to the pool of responses. I could certinly come up with some entertaining responses.
Reminds me of Microsoft's Elevation of Privilege card game, although this one was obviously designed with tongue-in-cheek. Still, everyone ought to click through a few excuses and think whether they are relevant to the systems we maintain.
Interestingly my malware and adblocking lists (via pfblocker-ng) has blacklisted this site as a known bad site!
For origins, see bofh excuses: http://pages.cs.wisc.edu/~ballard/bofh/bofhserver.pl
"Upskilled our cafeteria staff" is the phrase of the day. Use liberally.
Just TY!
funny how this site is not https
Other than the increased CO2 footprint what would - in this particular case - be the benefit?
The standard HTTPS benefit of making it impossible for ISPs to inject into and/or modify the page, usually for stupid reasons.
That's the big thing that pushed me to add LetsEncrypt to my blog. I was on some Belgium sim card and the ISP injected some crap via JavaScript at the top of my website. I couldn't even read it; didn't properly detect language/locale, but it looked like some warning about being near my data limit.
That you actually get what the website sent you.
Genuinely curious, by what proportion does it increase CO2 footprint by? Tried searching online but couldn't find anything.
TLS takes considerably more watts of power on the basis it actually does more work and shuffles more electrons around the CPU. I suppose that loosely converts into carbon footprint.
However even if it is an issue, most sites sending 6 meg of JavaScript crap down that gets recompiled on every visitor’s machine, autoplaying videos and advertising would be doing more damage. So if anyone is going to complain they should probably start there...
However even if it is an issue, most sites sending 6 meg of JavaScript crap down that gets recompiled on every visitor’s machine, autoplaying videos and advertising would be doing more damage. So if anyone is going to complain they should probably start there...
A proxy can't cache the ressources anymore.
SSL overhead, CPU used by both parties to do the encryption.
But the ISP can't alter the page.
I think the idea is that if you refresh the page you get another random excuse.
It is a bit silly but as someone who cares about security, almost everything that helps to bring attention to the widespread problems this industry has with security is good, -even if it is a bit silly.
It is a bit silly but as someone who cares about security, almost everything that helps to bring attention to the widespread problems this industry has with security is good, -even if it is a bit silly.
Why on earth did this make it to the front page. What a silly site.
"Haha some company got breached and they made decisions I consider a mistake. Haha they hired a CISSP,how lame."
How marvelously retarded. How about demonstrating some understanding of the complexities and difficulties involved in securing any large corporation? How about suggesting some solutions?
I can tell you one problem clearly: Management and C-suite do not get clear,useful and actionable security risk analysis with what practical solutions exist. I can also tell you idiots who communicate this way are worse than actual hackers trying to breach companies.
Of course there is a bigger problem of legal accountability which is a law making and voter education problem.
Oh and regarding CISSPs, do you have any idea how hard it is to hire people that know their tradecraft? Even for a decent salary and benefits and schedule? Very difficult if you're not a fortune 100! Would OSCP impress you? Wth is a guy who only knows pentesting worth unless you're hiring for a pentester? Heck, a CISSP that can't even code but undetstands security threats/risk and can communicate is worth 20 OSCPs for most orgs!
"Haha some company got breached and they made decisions I consider a mistake. Haha they hired a CISSP,how lame."
How marvelously retarded. How about demonstrating some understanding of the complexities and difficulties involved in securing any large corporation? How about suggesting some solutions?
I can tell you one problem clearly: Management and C-suite do not get clear,useful and actionable security risk analysis with what practical solutions exist. I can also tell you idiots who communicate this way are worse than actual hackers trying to breach companies.
Of course there is a bigger problem of legal accountability which is a law making and voter education problem.
Oh and regarding CISSPs, do you have any idea how hard it is to hire people that know their tradecraft? Even for a decent salary and benefits and schedule? Very difficult if you're not a fortune 100! Would OSCP impress you? Wth is a guy who only knows pentesting worth unless you're hiring for a pentester? Heck, a CISSP that can't even code but undetstands security threats/risk and can communicate is worth 20 OSCPs for most orgs!
It's a joke site, it generates random excuses for data breaches.
It's more funny because it's so often true.
Just like how many people get a dashcam after a crash, organisations tend to get serious after the breach.
Just like how many people get a dashcam after a crash, organisations tend to get serious after the breach.
> Just like how many people get a dashcam after a crash, organisations tend to get serious after the breach.
To the degree that they get serious that is. As far as I can see a big part of the joke here is that even that is questionable.
To the degree that they get serious that is. As far as I can see a big part of the joke here is that even that is questionable.
The part I liked is the idea that "We take your privacy and security seriously" is literally the "Thoughts and Prayers" of the data industry.
What's wrong with either one?
Ok,they claim to take security and privacy seriously,so what?? It's a freaking company! Would you prefer a thoughtful post on medium that uses simple language like "we were wrong and we accept full responsibility,here is what we learned..."? How about no response at all,is one owed to you?
Shouldn't they take privacy and security seriously? How is claiming to do so by itself a wrong? How are thoughts and prayers wrong? How are declarations of good intent mutually exclusive to meaningful action?
Ok,they claim to take security and privacy seriously,so what?? It's a freaking company! Would you prefer a thoughtful post on medium that uses simple language like "we were wrong and we accept full responsibility,here is what we learned..."? How about no response at all,is one owed to you?
Shouldn't they take privacy and security seriously? How is claiming to do so by itself a wrong? How are thoughts and prayers wrong? How are declarations of good intent mutually exclusive to meaningful action?
Serious as in minimize loss not serious in they now care about security.
True!
That why I hate it and made my cmment. I strongly disagree with the narrative they push under the guise of a joke. Very arrogant and shallow
Random excuses presumed to be funny because they're wrong. I disagree strongly with most of them and I hate the oversimplification it promotes. I hate that it promotes this stupid attitude that companies are stupid and unethical because they don't care about infosec as much as they should.
People who think this is funny probably also blame users for being too stupid/ignorant for most security incidents. Haha,users management even other IT workers are dumb. Everyone is ignorant except the elite infosec hackers...you can see why it's difficult to listen to anything someone with this attitude has to say. If no one listens to you,you can't educate them. If you're not willing to listen and understand others' perspective they will ignore yours,even if your peers think you're the best hacker ever!
People who think this is funny probably also blame users for being too stupid/ignorant for most security incidents. Haha,users management even other IT workers are dumb. Everyone is ignorant except the elite infosec hackers...you can see why it's difficult to listen to anything someone with this attitude has to say. If no one listens to you,you can't educate them. If you're not willing to listen and understand others' perspective they will ignore yours,even if your peers think you're the best hacker ever!
Jokes and silly comments are often downvoated, flagged and even against some of the rules here. Sure,HN is not Reddit ... so when something like this makes the top, it actually does feel kinda nice.
It may be silly, but it gave me a chuckle in an otherwise sad and terrible world. That is worth something today, I think.
It may be silly, but it gave me a chuckle in an otherwise sad and terrible world. That is worth something today, I think.
Silly as in dumb. Not silly as in funny. I got that it wad a joke but I hate the false premise and narrative it pushes. People actually believe some of that crap
Your whole post both misses the point of this site and misses the blame for the points you raise.
> How about suggesting some solutions?
Why not contact the makers of the site and ask them? It's pretty clear they made this website for a little bit of marketing for a security training vendor:
> Reflare is an IT Security training company helping executives and IT professionals create more secure organizations.
My personal $0.02 is to look at what Salesforce did. They hired pen testers to hack their board members and to reveal to each of them their most personal / valuable / embarrassing data. That breaks the ice and loosens the purse strings. Spend on a security team like a financial institution would. Then the entire company institutes "distributed security": gamification mechanics applied to all aspects of security. Incentivize _every_ _single_ _employee_ and contractor to be involved in security. Give out quarterly tropical vacataions to _any_ employee which improves company security the most. Train them -- every single hire. Compartmentalize + least privilege.
> Haha they hired a CISSP,how lame
The site randomly picks from an array of mitigations:
> Management and C-suite do not get clear,useful and actionable security risk analysis
Management and the C-Suite exist to hire the team that can give them the information + performance they want. It sounds like the C-Suite needs to learn what they don't know and then hire a CIO+CISO.
In the end, there is a risk trade-off. Far too many companies just "accept the risk" or simply buy cyber insurance (rather than investing in risk mitigations) then get breached. Far too few companies get liquidated when they get breached, sending a bad signal to their competition. Most companies don't want to lock down their product to absolute minimum risk (because that is fantastically expensive) and just aim to spend "the industry average" on security.
> How about suggesting some solutions?
Why not contact the makers of the site and ask them? It's pretty clear they made this website for a little bit of marketing for a security training vendor:
> Reflare is an IT Security training company helping executives and IT professionals create more secure organizations.
My personal $0.02 is to look at what Salesforce did. They hired pen testers to hack their board members and to reveal to each of them their most personal / valuable / embarrassing data. That breaks the ice and loosens the purse strings. Spend on a security team like a financial institution would. Then the entire company institutes "distributed security": gamification mechanics applied to all aspects of security. Incentivize _every_ _single_ _employee_ and contractor to be involved in security. Give out quarterly tropical vacataions to _any_ employee which improves company security the most. Train them -- every single hire. Compartmentalize + least privilege.
> Haha they hired a CISSP,how lame
The site randomly picks from an array of mitigations:
* made everyone promise to be super super careful
* gotten ISO certified
* gotten PCI certified
- worked with industry leading specialists
- upskilled our cafeteria staff
- hired external consultants
- worked with law enforcement
- bought an IDS
- twiddled with our firewall
- been pretty good about security
- hired some people with 'CISSP' after their names
- watched a YouTube video on cyber security
- told them to not do it again
- said that we are very sorry
- copy-pasted a security policy we found on Google
- hired a Russian dude
- watched the movie Hackers 8 times back to back
- sent one of our guys to Defcon
- put a rotating lock GIF on our website
Hiring a CISSP doesn't seem as ridiculous as the other options, but all things considered, I would rather a company hire CISSPs before they get breached. If they do it only after they get breached, I'd rather the company go bankrupt as a lesson the competition. I'm 100% in support of this website poking at Equifax because the post-breach repercussions have been far too lenient on the company and I hope every company fears bing "the next Equifax".> Management and C-suite do not get clear,useful and actionable security risk analysis
Management and the C-Suite exist to hire the team that can give them the information + performance they want. It sounds like the C-Suite needs to learn what they don't know and then hire a CIO+CISO.
In the end, there is a risk trade-off. Far too many companies just "accept the risk" or simply buy cyber insurance (rather than investing in risk mitigations) then get breached. Far too few companies get liquidated when they get breached, sending a bad signal to their competition. Most companies don't want to lock down their product to absolute minimum risk (because that is fantastically expensive) and just aim to spend "the industry average" on security.
Money is hardly the problem,justifyin spending is. Same goes for hiring, lack of people who know enough to be a general practitioner or architect is the problem not spending.
> It sounds like the C-Suite needs to learn what they don't know and then hire a CIO+CISO.
How???? You don't know what you don't know and you can only spend so much. A CISO that knows infosec is not easy to find.
Like i said in my comment what companies do is based on incentives. If you believe they should be more liable then get laws passed and their risk assesment will justify the spend.
Truth be told financial and reputation loss are the only concerns for a business,why is that surprising? They should be more responsible? Yeah...that's not how capitalism works, IT is an expense that you make up for using your revenue sources,doesn't pay for itself directly. You want them to spend 1M/year on a decent CISO and 200k+ on a team of security experts? Imagine how silly that would be for most companies with less than 5k employees! Give them a legal incentive and make security better using other avenues such as better IT products and services (which many are doing)
Oh and about salesforce...their main business is IT! They have quite a sizable revenue and a breach would affect that precious revenue very significantly. As opposed to say...home depot,99% of their customers who don't work in IT never even heard of their breach,heck I meet people in infosec who haven't either and they shop at homedepot just fine. Also,when a lot of companies are breached their stock either remains unaffected or it actually goes up because the breach is PR!
To me the whole thread and site is showing me the scale of the infosec bubble/echochamber. Too bad for karma though :)
> It sounds like the C-Suite needs to learn what they don't know and then hire a CIO+CISO.
How???? You don't know what you don't know and you can only spend so much. A CISO that knows infosec is not easy to find.
Like i said in my comment what companies do is based on incentives. If you believe they should be more liable then get laws passed and their risk assesment will justify the spend.
Truth be told financial and reputation loss are the only concerns for a business,why is that surprising? They should be more responsible? Yeah...that's not how capitalism works, IT is an expense that you make up for using your revenue sources,doesn't pay for itself directly. You want them to spend 1M/year on a decent CISO and 200k+ on a team of security experts? Imagine how silly that would be for most companies with less than 5k employees! Give them a legal incentive and make security better using other avenues such as better IT products and services (which many are doing)
Oh and about salesforce...their main business is IT! They have quite a sizable revenue and a breach would affect that precious revenue very significantly. As opposed to say...home depot,99% of their customers who don't work in IT never even heard of their breach,heck I meet people in infosec who haven't either and they shop at homedepot just fine. Also,when a lot of companies are breached their stock either remains unaffected or it actually goes up because the breach is PR!
To me the whole thread and site is showing me the scale of the infosec bubble/echochamber. Too bad for karma though :)
Yeah, that feels pretty accurate for today's political climate.
I love fun toys like this and would love an awesome list of them if anyone has one.