What Should We Do About Security Ethics?
An anonymous reader writes "I am a senior security xxx in a Fortune 300 company and I am very frustrated at what I see. I see our customers turn a blind eye to blatant security issues, in the name of the application or business requirements. I see our own senior officers reduce the risk ratings of internal findings, and even strong-arm 3rd party auditors/testers to reduce their risk ratings on the threat of losing our business. It's truly sad that the fear of losing our jobs and the necessity of supporting our families comes first before the security of highly confidential information. All so executives can look good and make their bonuses? How should people start blowing the whistle on companies like this?"
Ignore it?
factor 966971: 966971
So you're saying that you're a Muslim?
Of course, you'll lose your job over it. So decide now. Do you want to sleep at night? Or do you want to feed your family? That is one end of the spectrum. Another is to gather some evidence in order to ensure job security and hefty pay raises!
Awwww, the user behind this AC post must be really PMSing today to mod me down.
Last month Jim turned in his two weeks' notice.
By the way, we've got an entry level opening some of you might be interested in, just need a PhD, 10 years experience in C#, salary starts at $45k. Oh, and you have to be named Jim. Just send your resumes to jack@example.com...
If I have been able to see further than others, it is because I bought a pair of binoculars.
There are some really scary ones in there.
Google
Bank of New York
SAIC
Amazon.com
But my bet is on Toys "R" Us
Money is the root of all evil?
"I don't wanna patch up, I'm a Toy's R Us admin, there's a million exploits at Toys' R Us that I can pwn with!"
Horns are really just a broken halo.
unknown intruders penetrated xxx, because of security failure yyy you have always complained about, and the only reason you just happened to catch it is because you implented zzz as an afterthought
Of course, if that was an xxx double-penetration everyone would take notice immediately...
In the free world the media isn't government run; the government is media run.
Free tutorials about ethics in IT security are available from http://www.theregister.co.uk/odds/bofh/