Whenever someone gets infected I hear a lot of “Oh, it was socially engineered so it was there fault” or “Oh, it was an exploit, they should have updated and it’s their fault” or “Oh, the IT Admin should have locked the system down further” etc. People love to attribute blame to someone – I think it helps them feel safer to try to explain the situation in their mind.

Yes, there are situations where one party can be held more responsible than another but you can find blame for everyone in every situation. Got exploited through an old Java vulnerability? Well Oracle still has awful security. The user could have patched it. The OS could have taken responsibility for its security model.

There’s no point attributing blame to one party. It’s anti-security. The whole generational idea of “layers” implies that the ‘fault’ is spread throughout the system.

If you’re going to blame someone just blame the hacker. Way more clear cut.



blog comments powered by Disqus

Published

14 July 2012

Categories