Hacker News new | ask | show | jobs
by watertom 2759 days ago
I'm an Information Security and Privacy professional, and until there are real penalties for a lack of security nothing will change.

Go see the Ford Pinto case, cheaper to pay lawsuits from deaths than fix the problem, then don't fix the problem.

The other problem is an utter and total lack of technical knowledge by Sr. Management, they hire charming idiots who tell Sr. Management what they want to hear. I've been to conferences and I've listened to discussions from "security professionals" and I'd swear I was at my local supermarket asking people about Information Security and Privacy.

1 comments

The appearance of security is much more important than actual security. I would gander that is precisely because there is no real penalty outside of anything that would be considered the cost of doing business.

How to enforce punitive action upon a company with such international reach is the real question.