Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

61–70 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#61

Earlier quoted context omitted.

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

I'd like to hear more about this training - I have started to put together some resources to teach C suite, maybe new-to-the-field lawyers, other interested stakeholders - about website compliance issues.. looking to mimic other good training / learning materials, extra info to consider, maybe collab and send business I can't take on, etc.

Not the person you are replying to, but I work in security and have spent ~5 years of my career helping various companies set up and maintain security awareness programs.

There are some out-of-the-box solutions that can start you on your way to creating a security awareness training program, such as KnowBe4 and ProofPoint (there are others as well, but these are some of the big names). If you don't have in-house security staff, these types of offerings can be quite helpful.

For a more grounds-up approach, there are guidelines such as the NIST SP 800-50 "Building a Cybersecurity and Privacy Learning Program" guidance. (https://csrc.nist.gov/pubs/sp/800/50/r1/final)

If you have specific questions, I can try to answer them.

Re: FTC takes action against GoDaddy for alleged lax data security

#62
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

They profit a lot from uninformed CTOs and founders just going for whatever they heard of, instead of looking into whether it is a good provider, footing their businesses on shaky foundations.

Yeah - selection bias and apathy is the root of it, IMO.

GoDaddy attracts the unwashed masses who don’t care about security, and who remain unphased after learning about breaches. Meanwhile, the tech-savvy crowd who would care about breaches already know to avoid GoDaddy and view the inevitable breaches as the plebs reaping what they’ve sown.

Ergo, no one getting breached by GoDaddy cares, and nobody informed watching it happen feels a need to intervene.

Re: FTC takes action against GoDaddy for alleged lax data security

#63
post #4

I guess its just the power of advertising but its amazing to me that GoDaddy continues to be a popular solution for hosting, domain registration, etc given their absolute toilet of a reputation.

They bought out another registrar I was a customer of. Now I am paying 40% more for renewals. If I want to migrate I need to expose my whois info. They're always looking to upsell me into some horrible hosting garbage.

Update your whois to bogus information, transfer the domain, restore whois information. Cloudflare is the cheapest domain registrar long-term, you might get cheaper ones for the first year or first 3 years.

Re: FTC takes action against GoDaddy for alleged lax data security

#64
post #39

Earlier quoted context omitted.

They bought out another registrar I was a customer of. Now I am paying 40% more for renewals. If I want to migrate I need to expose my whois info. They're always looking to upsell me into some horrible hosting garbage.

Can you temporarily change your whois info before you migrate to somewhere else?

I've had some registrars lock the domain from transferring for a few weeks after changing whois.

Re: FTC takes action against GoDaddy for alleged lax data security

#65
post #61

Earlier quoted context omitted.

I'd like to hear more about this training - I have started to put together some resources to teach C suite, maybe new-to-the-field lawyers, other interested stakeholders - about website compliance issues.. looking to mimic other good training / learning materials, extra info to consider, maybe collab and send business I can't take on, etc.

Not the person you are replying to, but I work in security and have spent ~5 years of my career helping various companies set up and maintain security awareness programs. There are some out-of-the-box solutions that can start you on your way to creating a security awareness training program, such as KnowBe4 and ProofPoint (there are others as well, but these are some of the big names). If you don't have in-house secu…

As a technically-minded person, I've found both KnowBe4 and ProofPoint trainings to be very lacking/boring/superficial.

Re: FTC takes action against GoDaddy for alleged lax data security

#66
post #54

Earlier quoted context omitted.

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

Crowdstrike took down all windows boxes that had their software installed and didn’t really affect them.

I think customers feel, rightly or wrongly, there's no alternative to CrowdStrike.

There are so many alternatives to what GoDaddy provides, it is quite commoditized.

But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...

Re: FTC takes action against GoDaddy for alleged lax data security

#67
post #64
post #39

Earlier quoted context omitted.

Can you temporarily change your whois info before you migrate to somewhere else?

I've had some registrars lock the domain from transferring for a few weeks after changing whois.

It's called the 60 day registrant change lock. Most changes to administrative or technical contact information will trigger it.

Although it's a real ICANN rule, the registrar is allowed to override it if they want. Of course very few registrars offer that kind of customer service, so that escape hatch might as well not exist...

Re: FTC takes action against GoDaddy for alleged lax data security

#68
post #58
post #40

Earlier quoted context omitted.

Uh, is Trump's mouth during both of his presidential campaigns citation enough? He's not even shy about his, um, desire for fealty.

Then link it unedited. He's an asshole, I get it. But half of what is said about him is false (pee pee tapes?) that Americans don't give a darn about what is true.

Stop asking people to do unpaid labor for you.

Re: FTC takes action against GoDaddy for alleged lax data security

#69
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

The elephant in the room may be GoDaddy's historical total disregard for security, but hey, those pesky elephants won't shoot themselves! GoDaddy CEO's graphic elephant hunt video sends his clients flocking to competitors, and helps raise $20,000 for elephant charity: https://www.dailymail.co.uk/news/article-1374679/GoDaddy-CEO... GoDaddy CEO Kills Elephant: https://www.youtube.com/watch?v=YnM5yTW2B3g

Bob hasn't been CEO of GoDaddy since 2011

Re: FTC takes action against GoDaddy for alleged lax data security

#70
post #61

Earlier quoted context omitted.

Not the person you are replying to, but I work in security and have spent ~5 years of my career helping various companies set up and maintain security awareness programs. There are some out-of-the-box solutions that can start you on your way to creating a security awareness training program, such as KnowBe4 and ProofPoint (there are others as well, but these are some of the big names). If you don't have in-house secu…

As a technically-minded person, I've found both KnowBe4 and ProofPoint trainings to be very lacking/boring/superficial.

While I agree with you, that's why they are a starting point for someone looking to stand up a program, not an end point.

And, from my experience, many of the trainings that seem almost offensively easy to me (e.g. "How to read a URL") have been some of the ones that received the most positive feedback from non-technical departments.

The real key with security awareness training is ensuring the training is at the appropriate level of complexity for the trainee.

Post reply on HN