Earlier quoted context omitted.
>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…
As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.
FTC takes action against GoDaddy for alleged lax data security
81–90 of 181 posts
Re: FTC takes action against GoDaddy for alleged lax data security
#82Earlier quoted context omitted.
Not the person you are replying to, but I work in security and have spent ~5 years of my career helping various companies set up and maintain security awareness programs. There are some out-of-the-box solutions that can start you on your way to creating a security awareness training program, such as KnowBe4 and ProofPoint (there are others as well, but these are some of the big names). If you don't have in-house secu…
As a technically-minded person, I've found both KnowBe4 and ProofPoint trainings to be very lacking/boring/superficial.
Re: FTC takes action against GoDaddy for alleged lax data security
#83It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…
I have had to tell multiple cybersecurity vendors that brag about working with huge companies and governments that we cannot work with them because of how poor their own cybersecurity practices are (i.e. not using secure compute/hardware crypto when dealing with our private keys).
These are companies that should know better, I have had to stop ADP professional services more than once from disabling certificate validation on critical pipelines pertaining to confidential employee and customer information. I do not want to imagine what happens at 99% of companies with cybersecurity teams that don't even know what certificate validation is.
Re: FTC takes action against GoDaddy for alleged lax data security
#84Earlier quoted context omitted.
Is the US turning into "fourth Reich"?
Luckily we have enough remaining guardrails that it's unlikely to happen within the next 4 years. But we're getting closer, that's for sure. And the Supreme Court's disastrous decision on presidential immunity is allowing Trump to play Generalissimo.
Trump already "deported" legal american citizens his first term. Trump supporters openly insist on "deporting" a legal american citizen who dared to tell Trump that he's a meany.
The Constitution is just a piece of paper. None of the people in the Trump admin care about it or respect it. It will not save us. The guardrails are all gone.
Re: FTC takes action against GoDaddy for alleged lax data security
#85Earlier quoted context omitted.
As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.
So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data. If it can't hit the bottom line bigcorps don't care; liability is the only language they understand.
Re: FTC takes action against GoDaddy for alleged lax data security
#86Earlier quoted context omitted.
>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…
> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.
Re: FTC takes action against GoDaddy for alleged lax data security
#87It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…
It's a tough business hosting arbitrary UGC, and doing it well costs a lot of time effort and money (ask me how I know). But I fully agree: treating this as just another line-item cost is absurd.
Re: FTC takes action against GoDaddy for alleged lax data security
#88Earlier quoted context omitted.
Luckily we have enough remaining guardrails that it's unlikely to happen within the next 4 years. But we're getting closer, that's for sure. And the Supreme Court's disastrous decision on presidential immunity is allowing Trump to play Generalissimo.
What guardrails are you talking about? Even ignoring the presidential immunity ruling that explicitly makes him Fuhrer, if Trump has ICE arrest all brown people tomorrow, what exactly is going to stop him? The courts? A judge can say whatever the hell they want from their bench, it won't stop an ICE agent from physically forcing you onto a C130 and taking you wherever. Trump already "deported" legal american citizens…
And you're right, ICE could well be on its way to turning into the Stasi.
Re: FTC takes action against GoDaddy for alleged lax data security
#89It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…
Re: FTC takes action against GoDaddy for alleged lax data security
#90Earlier quoted context omitted.
So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data. If it can't hit the bottom line bigcorps don't care; liability is the only language they understand.
So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"