Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

41–50 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#41
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

As SRE, I've heard executives say this "There is no penalty for breaches, why care?"

Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected.

We get training on it every six months.

Re: FTC takes action against GoDaddy for alleged lax data security

#42
post #16

I was shocked when I purchased a domain recently on GoDaddy (I normally use Cloudflare or AWS) and noticed that they have an 'upsell' with more security options (MFA and some other features) for something like $10/yr. Why wouldn't they want their customers to be more secure by default? To me it just reeks of money-grabbing for people that are none the wiser.

It is outrageous and irresponsible to charge for MFA. It show a cavalier attitude toward the greater security of the internet.

Same for OIDC (and even traditional SAML SSO).

If every stolen or potentially stolen credential was billed to the breached provider at even $100/account*, SSO would become free so fast your head would spin.

Every credential in the provider's DB would be correctly seen as a liability.

* Arguably the number should be higher and contribute to a infosec response, detection, and preventative measures warchest. Though, ultimately, this would probably just enrich cybersecurity insurance firms.

Re: FTC takes action against GoDaddy for alleged lax data security

#43
post #37

Earlier quoted context omitted.

I am not sure what you mean by falsified but is this OK? https://www.independent.co.uk/news/world/americas/us-politic... "Incoming senior Trump administration officials have begun questioning career civil servants who work on the White House National Security Council about who they voted for in the 2024 election, their political contributions and whether they have made social media posts that could be considered incr…

[flagged]

I am considering this in the context of 1930's history.

Re: FTC takes action against GoDaddy for alleged lax data security

#44
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

They profit a lot from uninformed CTOs and founders just going for whatever they heard of, instead of looking into whether it is a good provider, footing their businesses on shaky foundations.

They profit a lot from uninformed CTOs and founders just going for whatever they heard of, instead of looking into whether it is a good provider

If it wasn't for those old Super Bowl ads, GoDaddy wouldn't exist today.

Sex sells.

Re: FTC takes action against GoDaddy for alleged lax data security

#45
post #39

Earlier quoted context omitted.

They bought out another registrar I was a customer of. Now I am paying 40% more for renewals. If I want to migrate I need to expose my whois info. They're always looking to upsell me into some horrible hosting garbage.

Can you temporarily change your whois info before you migrate to somewhere else?

[deleted]

Re: FTC takes action against GoDaddy for alleged lax data security

#46
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?"

Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

Re: FTC takes action against GoDaddy for alleged lax data security

#47
post #4

I guess its just the power of advertising but its amazing to me that GoDaddy continues to be a popular solution for hosting, domain registration, etc given their absolute toilet of a reputation.

I don't use GoDaddy, but I had to transfer some domains of NetSol a couple months ago, and it made my experiences with GoDaddy look like a happy dream.

People will put up with all kinds of awfulness if they don't know better.

Re: FTC takes action against GoDaddy for alleged lax data security

#48
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

The elephant in the room may be GoDaddy's historical total disregard for security, but hey, those pesky elephants won't shoot themselves!

GoDaddy CEO's graphic elephant hunt video sends his clients flocking to competitors, and helps raise $20,000 for elephant charity:

https://www.dailymail.co.uk/news/article-1374679/GoDaddy-CEO...

GoDaddy CEO Kills Elephant:

https://www.youtube.com/watch?v=YnM5yTW2B3g

Re: FTC takes action against GoDaddy for alleged lax data security

#49
post #37

Earlier quoted context omitted.

I am not sure what you mean by falsified but is this OK? https://www.independent.co.uk/news/world/americas/us-politic... "Incoming senior Trump administration officials have begun questioning career civil servants who work on the White House National Security Council about who they voted for in the 2024 election, their political contributions and whether they have made social media posts that could be considered incr…

[flagged]

> So Trump is demanding loyalty from the members of the National Security Council. Not the FTC. Not the DOE.

No. He's demanding loyalty from everyone.

Re: FTC takes action against GoDaddy for alleged lax data security

#50

Earlier quoted context omitted.

Federal employees are being asked who they voted for. This is not hyperbole.

Is the US turning into "fourth Reich"?

Luckily we have enough remaining guardrails that it's unlikely to happen within the next 4 years. But we're getting closer, that's for sure. And the Supreme Court's disastrous decision on presidential immunity is allowing Trump to play Generalissimo.
Post reply on HN