Remix.run Logo
starvar2 2 hours ago

Who takes the fall for mistakes like this?

stronglikedan 2 hours ago | parent | next [-]

The system, so no one in particular, so it will never get better until individuals can be held accountable.

popeyeparrot 2 hours ago | parent | next [-]

Its easy to say someone being personally responsible would fix the problem.. Really this just encourages further nefarious organizational behavior. I.e. hiring people into big titles who can't even understand their liability and railroading them into what an informal management actually wants as far as risk/cost trade offs which are then even higher toward risk as there is a scapegoat.

nekusar 2 hours ago | parent | prev [-]

Policy makers make the policy that must be followed. Of course the engineers would take the brunt of blame, even though the engineering groups never make policy.

hvb2 an hour ago | parent | prev [-]

Let's presume this is a company, who would you say should take the fall for this?

The CEO will have to talk about it and manage the fallout. What else are you looking for.

Also, at this point we have no idea how they got in, until we know I think we should withhold judgement. Unless you consider yourself responsible if someone ever gets into a system you manage with a zero day.

Security is not an exact science, it's a trade-off between sensitivity of the data and the cost of protecting it whether you like it or not

Xmd5a an hour ago | parent [-]

Punishment isn't an exact science either, and there will be some arbitrary decisions that will be taken in order to find a trade-off between visibility and responsibility, whether you like it or not