Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Sounds like a good idea, but then when you have an outage, you have to scramble to find multiple people to unlock the access keys and watch over your shoulder while you make fixes on production systems.

While I can understand that seems like a huge pain for a legitimately acting company, this is exactly the type of thing I would want to see a law like this enact. Sure, it slows down fixes when there are problems, but it sounds like it might have helped with past stuff like the Crazy Eddie fraud[1]. There's likely a spectrum between what happened there and what a respectable company like yours does, and requiring few keys to change this data and oversight while doing so likely helps quite a bit with operational incompetence as well.

> Another great example is password rotation. The law demands you have a password rotation policy. It doesn't say what that policy should be. Most auditors have settled on 90 days.

I've experienced this with PCI Compliance. It's annoying, but you have to realize that there are a lot of people and companies out there that have no idea about proper security, or continuously deprioritize it in favor of some other thing they need to get done. It's never a big deal until it is, then it's a huge deal. Making it mandatory, even if it overshoots a bit and is more cumbersome that it needs to be is beneficial overall because there are a lot of people like I described.

And that's sort of how I see these laws overall. For the people that are already mostly compliant it's burdensome, but if those people and companies are actually 10-20% of the market and the other 80-90% aren't really following best practices and are ripe for problems, whether they be security, management, operational or criminal, then I don't really care if it's somewhat burdensome for those 10-20%. If the companies that are using best practices already are 80-90% or more of the market, then sure, the law might be too burdensome for the benefit it infers (but it might not, depending on how bad the problems it prevents are).

And that's really the crux of the issue. How burdensome the law is to responsible companies is irrelevant without the context of how often it is useful to force the hands of irresponsible companies. How big is the group your company, as a responsible actor, represents? That's the missing information here.

1: https://news.ycombinator.com/item?id=13844316



That's a fair point. I've only ever worked for responsible companies.

If the checklists are actual implementations at the other companies, then yes, maybe there is some value there. But then the law could still be improved to allow a little more leeway for companies that are responsible. I don't know how that would work though.


> But then the law could still be improved to allow a little more leeway for companies that are responsible.

Bad companies already try their darndest to present as responsible, and if they never succeeded there wouldn't have been call for these regs in the first place. I don't think making a determination as to who "is responsible" and loosening requirements makes any sense - Enron and WorldCom would probably have been "responsible".

Better would be to try and align the regulations so that they have minimal friction while people are acting responsibly. Maybe you don't need a key and active oversight to make a change - maybe the change can be logged non-destructively and audit can happen after the fact.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: