People ask me all the time what I do for work. It's one of those things where if I try to explain it, I usually get a blank look. My mom just knows I've been successful in my career. My brother has a vague idea it has something to do with that little lock in your browser when you visit your bank. When I'm not in the mood to get into it, I just say "computer security," which gets me one of two reactions: "oh, maybe you can help me with my laptop," or an immediate and total loss of interest.
I've spent twelve years working with Active Directory Certificate Services. No, I haven't run one of the global trust hierarchies that quietly hold up the entire internet. But I have designed and built the systems that sit directly on top of millions of people's personal data. Health agencies across North America, all of them trying to protect patient information that's about as private as information gets. Financial institutions, where one badly configured system can turn into a very real problem for somebody's money. Universities, colleges, police forces, municipal governments, oil and gas. I've had a hand in the PKI behind most industries you can name.
I can't tell you which ones — the NDAs are longer than this article — but the odds are pretty good I've helped secure something that touches your life by fewer than seven degrees of Kevin Bacon.
I'd love to tell you all those clients took the recommendations seriously and understood what was at stake. The truth is most of them don't really know what their PKI does for them, and fewer still understand how a bad design turns into a bad day. And these aren't small failures when they come. A certificate authority nobody planned to renew. A root that quietly expires and takes authentication down for an entire network at 2am — while the people who actually need to log in to do their jobs sit there locked out. That's not a hypothetical I read about. That's the kind of thing I get called in to clean up.
Which brings me to the part that stuck with me after twelve years of this.
There are companies I now avoid. Not because of anything they'd ever admit to publicly — their websites all have the same reassuring paragraph about how seriously they take your privacy — but because I've been in the room. I've seen the "risk tolerance" up close. I've watched an organization look at a known, fixable problem and decide it was too inconvenient, too expensive, or that it "wouldn't affect them anyway." Famous last words. After you've heard that a few times, from the inside, you start keeping a private list. I won't hand those companies my identity, my money, or my information if I can avoid it — and I know exactly why.
Here's the uncomfortable part for the rest of you: you can't make that list, because you were never in the room. The fancy website tells you nothing. And when it goes wrong, it usually isn't the company that pays the real price. Disclosure laws have come a long way, but they're applied unevenly, and the bill still lands on the customer or the citizen. Us.
So no, I don't think most people actually know whether the businesses they trust are protecting their data. I've seen too many that weren't. I just have the unfair advantage of knowing which ones.
