Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For most corporations, security and robustness are -- and for a long time have been -- an afterthought.

Making systems hard to hack and robust to rare events:

* is really hard,

* costs a lot of money, and

* reduces earnings in the short term.

Faced with these inconvenient facts, many executives who want to see stock prices go up prioritize... other things.



To them, they are thinking about it though. They installed this ultra secure thing called CrowdStrike that checked a regulatory box for cybersecurity


CrowdStrike is a textbook example of a single point of failure:

https://en.wikipedia.org/wiki/Single_point_of_failure


To be fair, most corporations signed up for Crowdstrike as a way to address some issues. I'm sure it wasn't cheap and CS was probably better at security than an IT admin at a 50 person shop.


But what's worse, hundreds of maybe insecure companies or creating a big single point of failure?


Globally or locally?

To each individual company, it’s better to have the big single point of failure. That’s the problem.


Much like the RSA attack, now we get to see how Crowdstrike handles damage control.


Yeah, it wasn't cheap.

It's still not enough.


I feel like I would be doing everything in my power to de-Windows my operation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: