Something Is Getting Harder
· From the 2010–2013 blog
Hehe. So one of the other things Steve and I have been talking about lately is security. What to harden, and how. How to do things like intrusion detection, and how to handle accounts when you have to fire people. Its all pretty hand wavy stuff, and it really is a sliding scale between really shitty and kinda sorta protected, with perfect way out of reach. and in the end it really only ever matters if someone decides they want to make your life miserable. The big thesis we've had so far is the you attack problems in 3 different ways.
- First, for anything moderately social - you attack it from a social perspective. Make sure people know you will press charges and come after them. Make sure your employees are happy and reviewing each others code. Make sure lying is bad, and trying to do sneaky things is also bad. and just generally champion a sense of good and unity - we are all working to build something cool - do you want in or not?
- Second, harden as best as possible all public interfaces. SSH using keys only, lock down apache and mysql, run things like app armor and trip wire, and just generally do the 90% to make sure everything is pretty well sewn up.
- Third, audit things on a sliding scale. HR and accounts style stuff needs to be kept super safe and highly audited, while the source code can be reasonably public. Somewhere in the middle lies everything else. Audit, and peer review as best as possible, and manage a single-source for removing peoples permissions and changing external service passwords.
Beyond the guidelines above you just hire good people and do your best. If you get hacked, you clean it up and go after whoever did it as best you can. you keep backups so you can try and mitigate the worst case, and you to some point keep your fingers crossed. as far as i can tell its an ongoing process where you keep up with the 90% mark on the curve and you'll be fine.