Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because the people who implement the login systems aren't always security professionals. Sometimes they're random, mediocre, software engineers who don't really care about security, but their boss put them in charge of the website.


And the boss isn't a security professional (or even a software engineer, half the time) so he doesn't care. In fact, there's commonly an entire culture all the way up the ladder where nobody gives a shit about security, so terrible holes stay wide open for years.


This is where the Anonymouses of the world are doing a real service for the world. People need to forced by real consequences to take security seriously.

There's not anything wrong with that either. As humans, we have limited available attention. You and I might argue that security is critical, but even thinking about everything that is reasonably deemed critical is paralyzing. Statistically organizations are just not going to take security seriously on the whole until they get pwned to the tune of billions.


I can't think of an example i've seen where Anonymous-like breaches caused anyone but the actually breached companies to reflect on their security (Sony didn't even react immediately, they got pwnd three times). Releasing personal information just isn't a threat to companies in the era of Facebook.


How would such an example be visible to you?


Does it really matter that they are/are not security professionals? Virgin Mobile is a major corporation, and (if I understand the vulnerability correctly) are willing to let a unique IP ping their server 1MM times in a day. Rate limiting software is open-source and easy to come by. How does Virgin mobile prevent DDOS attacks if this vulnerability exists?


Just because they're a major corporation doesn't mean anyone with any clout gives a shit about whether or not customer logins are being brute forced, or if their servers can be DDOS'd. Even if somebody cared to mention it, somebody else would mention that it's too expensive, they're not getting attacked right now, and there's more important problems to worry about, so it gets ignored. This is not just cynicism on my part - this is how most companies operate. When they start losing money they'll start caring about security.

Oh, and DDOS has nothing to do with rate limiting. If you fill up a pipe with incoming packets it's going to become unresponsive. There's no real way to stop it, but multi-homing, global distribution and some tricks administered by DDOS mitigation companies can help.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: