Comment Flawed Logic (Score 1) 220
From TFA:
Instead of focusing primarily on fixing vulnerabilities, businesses should turn toward deterring threats, including detecting attacks and responding to them, he said. There have to be penalties for attackers, Chabinsky added.
The problem with the logic here is, a company is trying to protect data that is worth, at least to them, possibly millions of dollars. The attacker can be using a crappy dell system and maybe a bot-net he acquired (somehow,) for a total cost of fuck all. Even if the company can respond and make the attackers gear explode (and really we are being very pie in the sky there aren't we) your still only inconveniencing the attacker fuck all. Even best case for the company with this response situation there is still very little for the attacker to loose for a possible great gain or great net result if the aim is sabotage. Moral problems aside, this does not make economic sense in the end, there is no deterrent in most cases.
The only recourse for them is to prevent the attack (i.e. fixing vulnerabilities) and report breaches to the authorities. Unless responses include international bounty hunters?