ionwake
7 hours ago
Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
bombcar
7 hours ago
There's a very "child-like" (not in a good way) form of responsibility that everyone seems to lean into as they climb up - very intent-based.
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
ben_w
6 hours ago
> I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
And now we have the same thing but the bosses 'hire' AI.
Now I realise this is part of how unusual my thinking is.
I'm happy to use phrases like "ChatGPT hacked out of the sandbox, then hacked into HuggingFace"; people often respond to this like I'm suggesting OpenAI isn't at fault, and like, that's not my position at all, so far as I'm concerned the buck still stops with the person who set the task regardless, the thing that changes from incidents like this is now nobody in the future gets to even have the excuse "oh but we didn't know it could even do that" or "we didn't know it might interpret our orders in that kind of way".
The response, both when a human messes up and now when an AI messes up, needs to be defence in depth: someone giving orders needs to be giving clear orders, entities (human or machine) who follow instructions need to have not just an understanding of how to follow them, but also what's so out of scope as to be forbidden - the difference between 'follow orders' and 'follow lawful orders'.
soco
6 hours ago
You have a very engineer-like approach, like if you draw the line from A to B everything will work fine. Real world is different though. Humans will blissfully ignore the orders, business analysis is a lost cause since decades, and AI is built on human knowledge so guess what it will keep doing. Now what? How do we build systems without assuming complete adherence, but tolerating imperfection and failures? Isn't there some discipline teaching us that?
ben_w
6 hours ago
I indeed have a engineer-like approach, but engineering absolutely does not assume draw line from A to B and expect that's enough:
Real world, as you say, not so simple. Everything has to deal with certain degree of forecastable nonsense, e.g. a bridge has to cope not only with traffic and winds, but the possibility that someone will be drunk in charge of a ship and crash into it.
> AI is built on human knowledge so guess what it will keep doing.
Yes, and also brings its own additional mess on top of that. All machine learning takes a huge number of examples to get good, so an LLM isn't just "read all the online courses in how to run a business", but also likely has 50 business versions of the recent demonstration of common sense failure with "I live 100m from a car wash, should I walk or drive?"
> How do we build systems without assuming complete adherence, but tolerating imperfection and failures? Isn't there some discipline teaching us that?
Many such disciplines. Perhaps all except maths and computer science? Or even including maths and computer science, given stats is part of maths and even compsci has to deal with fault tolerance.
christophilus
5 hours ago
> Isn't there some discipline teaching us that?
That’d be engineering.
randysalami
4 hours ago
Yes and there is a reason, we are in theory, held to such higher standards. I used to think it was harder to draw the line with AI. The simple reason being when I as an engineer say something is not feasible (not not possible, just wrong and not worth doing), I could be overridden with AI. Now that we have more complex models == more money, I can draw the line with dollars and that is a language way stronger than technical feasibility to management.
jamescontrol
4 hours ago
Yes I completely agree. In the local news there was focus on which company it was and that the password was 123456.
Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.
Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.
mschuster91
4 hours ago
The older the system, the higher the chance it never got a proper security audit, and/or it was built with a lot of implied trust, like most old Internet standards are.
As for 2FA, it is a nice thing to have, but it comes at a significant support cost. People lose their token, people get annoyed by the friction, people can't figure out setup (especially older folks).
_bernd
4 hours ago
That's not how auditing works as I have observed it. Either your stuff is critical, or not. And when it is then everything which touches data sees an audit and no password policy incl. Shared and weak credentials is the first thing that would have been spotted. I would assume they buried some stuff to deep in a hierarchy and 3rd service partners that this company in the end got no proper audit.
edoceo
2 hours ago
Oh no! Cost! Friction! Better just half-ass it then.
Betelbuddy
4 hours ago
The security audit recommended changing the password to 234567, but management rejected it because it would require retraining staff
darepublic
39 minutes ago
When you have bad practice and process it can erode the security discipline of everyone working within the system. Until they commit brazen crap like reusing simple passwords everywhere.
al_borland
5 hours ago
They way I see it, there needs to be enough slack in an organization and the timelines for major products for people to not do the bare minimum. When management pushes goal X, and pushes hard, everything else starts to decay, including security. People need enough time to do the things they know they should do, but don’t feel they have the time for. At least this is where I’ve seen a lot of issues arise.
basilgohar
3 hours ago
The incompetence will continue as long as people can profit from it inconsequentially.
Our system now heavily reenforces lack of accountability to executives for what happens under their watch.
Investors don't lose money when these breaches happen.
This is why it won't change until those change.
miohtama
6 hours ago
Massive reorganisation will only happen if companies with poor security record go out of business, while competent ones win market share.
Otherwise shareholders do not care, because they do not have skin in the game.
Same for government staff. Unless they are explicitly fired there are no consequences of abusing the trust of public.
chrisjj
5 hours ago
> Massive reorganisation will only happen if companies with poor security record go out of business, while competent ones win market share.
... said every "security" pedlar ever.
lukan
5 hours ago
"I dont understand why there is not massive reorganisations in systems when things go wrong"
Because massive reorganisations can easily lead to even more things going wrong. Also most people are lazy and phlegmatic by default.
SoftTalker
2 hours ago
Let's also include the system itself, that allowed the account to have a password that short and apparently didn't require 2FA.
fierycatnet
4 hours ago
Im not in tech but still in corporate. Our store went through 6 GMs in 5 years. The problem is actually the corporate, not the new guy every 8 months who is being brought on to save the day. I think they're going to replace him again next year without addressing any of the issues on the ground.
asdf88990
6 hours ago
Rome wasn’t built in a day, not did it fall in a day. In a capitalist society you can gauge overall direction and success of the society but how well the market and private enterprise is doing, and well not merely in context of maximising shareholder value but as a fundamental part of the social fabric.
saghm
5 hours ago
I've tried reading your second sentence several times but I'm unable to parse it. What exactly are you trying to say?
chrisjj
5 hours ago
> I dont understand why there is not massive reorganisations in systems
This would just replace one insecure system with another.
It is time to recognise there's no such thing as a secure connected computer. And thanks to "AI" there's no such thing even as a significant defence lead over attackers.
coliveira
5 hours ago
A major problem we have is that computer programming is not engineering as people like to say. An engineering discipline VALUES redundancy and is always designing for safety. Programming likes to think of itself as math, and deliberately choses less redundancy for the sake of convenience and speed. The classical example is how operating systems are written with languages that allow an index to be out of bounds. We now have systems that are glued together using bubble gum pretending to be safe, when they fail in the most horrible way when one of the links break.
tokai
7 hours ago
Yeah that is a pretty weird opinion. Who cares about if he gets fired. He should be charged with criminal negligence and face prison time. Everyone is responsible for their own actions and its always possible to quit.
zweifuss
6 hours ago
The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.