Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

71–80 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#71

Earlier quoted context omitted.

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

Most customers use your product because it was on the first page of their Google search results.

The only people who's reputation gets ruined are the D-Level Directors and Managers who run this stuff and regularly run into budget or resource shortfalls that prevent them from doing all that they are capable of doing.

Re: FTC takes action against GoDaddy for alleged lax data security

#72

Earlier quoted context omitted.

It is outrageous and irresponsible to charge for MFA. It show a cavalier attitude toward the greater security of the internet.

Same for OIDC (and even traditional SAML SSO). If every stolen or potentially stolen credential was billed to the breached provider at even $100/account*, SSO would become free so fast your head would spin. Every credential in the provider's DB would be correctly seen as a liability. * Arguably the number should be higher and contribute to a infosec response, detection, and preventative measures warchest. Though, ult…

Agreed.

Another example is Microsoft charging extra for enhanced logging. This came to light during the SolarWinds debacle.

Re: FTC takes action against GoDaddy for alleged lax data security

#73

Earlier quoted context omitted.

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

The whole thread is related to GoDaddy's numerous breaches not affecting their bottom line or market position. So it seems lots and lots and lots of people really don't care.

Re: FTC takes action against GoDaddy for alleged lax data security

#74

Earlier quoted context omitted.

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data. If it can't hit the bottom line bigcorps don't care; liability is the only language they understand.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data

Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"

Re: FTC takes action against GoDaddy for alleged lax data security

#76

Earlier quoted context omitted.

The elephant in the room may be GoDaddy's historical total disregard for security, but hey, those pesky elephants won't shoot themselves! GoDaddy CEO's graphic elephant hunt video sends his clients flocking to competitors, and helps raise $20,000 for elephant charity: https://www.dailymail.co.uk/news/article-1374679/GoDaddy-CEO... GoDaddy CEO Kills Elephant: https://www.youtube.com/watch?v=YnM5yTW2B3g

Bob hasn't been CEO of GoDaddy since 2011

I know, that's exactly why I wrote "historic", but the current owners gave him an enormous amount of money, didn't clean up their act, and GoDaddy CONTINUES to be terrible.

The security breach we're discussing didn't happen 14 years ago, as you well know. They have a long and infamous track record and toxic corporate culture and unethical business practices and willfully misleading negligence of security that show no signs of improving.

So charming that you're on such a familiar first name basis with a piece of shit like Bob Parsons. Are you friends? Are you actually carrying the water for GoDaddy, or think it's ok to murder elephants and run incredibly sexist commercials while never giving a shit about security or customers? Yuck.

Re: FTC takes action against GoDaddy for alleged lax data security

#77
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

They are also the worst hosting provider I have ever worked with, multiple times. Awful customer support and high prices. The only reason I work with them anymore is to migrate new customers to a different provider.

Re: FTC takes action against GoDaddy for alleged lax data security

#78
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

So basically like Microsoft ?

Re: FTC takes action against GoDaddy for alleged lax data security

#79

Earlier quoted context omitted.

They bought out another registrar I was a customer of. Now I am paying 40% more for renewals. If I want to migrate I need to expose my whois info. They're always looking to upsell me into some horrible hosting garbage.

Update your whois to bogus information, transfer the domain, restore whois information. Cloudflare is the cheapest domain registrar long-term, you might get cheaper ones for the first year or first 3 years.

Using bogus whois info is a great way to lose your domain. If you are afraid of exposing your phone number and address, rent a P.O. box and get a throwaway number to use in the interim.

Re: FTC takes action against GoDaddy for alleged lax data security

#80
post #4

I guess its just the power of advertising but its amazing to me that GoDaddy continues to be a popular solution for hosting, domain registration, etc given their absolute toilet of a reputation.

An unofficial ranking of the most NSFW GoDaddy commercials ever: https://www.golfdigest.com/story/an-unofficial-ranking-of-th... The Woman(!) Behind GoDaddy's Tasteless, Effective Super Bowl Ads: https://www.forbes.com/sites/jeffbercovici/2013/02/06/the-wo... Who Let These Commercials Be On TV? https://www.youtube.com/watch?v=_rRopnyZaR0 GoDaddy's most infamous ads: https://www.youtube.com/watch?v=u7yFCqOAb9Y 10 SEXI…

Hilarious to see all the takedowns on these videos. Who the hell DMCA's a reposted advertisement? It's literally free advertising. The only reason they would take these down is because they were ashamed of them - and they probably should be.
Post reply on HN