|
|
|
|
|
by nonrandomstring
870 days ago
|
|
> Agencies running the affected products must assume domain accounts
associated with the affected products have been compromised. This looks like a right shitshow. Ross Anderson did a big group research "The Changing Cost of
Cybercrime" [0]. I forget the number but it came out at several
trillion. After Solarwinds and the UK Horizon Post Office scandal I am
wondering, how does cybercrime compare against simple incompetence
and hopelessly broken software engineering? How can we measure that to
see just how bad things really are? [0] https://weis2019.econinfosec.org/wp-content/uploads/sites/6/... |
|
There's very little cyber crime that happens by bribing someone. Most of it is just walking past an open door.
> How can we measure that to see just how bad things really are?
hence, cost of incompetence = cost of all cybercrime + n.