Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

91–100 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#91
post #54

Earlier quoted context omitted.

Crowdstrike took down all windows boxes that had their software installed and didn’t really affect them.

I think customers feel, rightly or wrongly, there's no alternative to CrowdStrike. There are so many alternatives to what GoDaddy provides, it is quite commoditized. But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...

I've actually not worked anywhere that has used CrowdStrike. It's usually ruled out as too expensive (I've mostly worked in public sector). I've had very good experiences with Sentinel One and Microsoft Defender. I've had terrible experiences with Trellix and Sophos."Oopsy" aside, is CrowdStrike really that much better than the competition?

Re: FTC takes action against GoDaddy for alleged lax data security

#92
post #91

Earlier quoted context omitted.

I think customers feel, rightly or wrongly, there's no alternative to CrowdStrike. There are so many alternatives to what GoDaddy provides, it is quite commoditized. But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...

I've actually not worked anywhere that has used CrowdStrike. It's usually ruled out as too expensive (I've mostly worked in public sector). I've had very good experiences with Sentinel One and Microsoft Defender. I've had terrible experiences with Trellix and Sophos."Oopsy" aside, is CrowdStrike really that much better than the competition?

The big four (CRWD, S1, Prisma, and MDE) all mostly comparable tbh.

EDR (especially Windows EDR) is heavily commodified.

Re: FTC takes action against GoDaddy for alleged lax data security

#93
post #54

Earlier quoted context omitted.

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

Crowdstrike took down all windows boxes that had their software installed and didn’t really affect them.

Crowdstrike's security reputation matters a lot more. I'll bet the customers assume the competitors have the same reliability problems, they can tolerate a little downtime, and going with nobody is even worse.

Re: FTC takes action against GoDaddy for alleged lax data security

#94
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

GoDaddy had really good marketing at one point and as of the last time I used it, which was years ago, they make it very difficult (I'm pretty sure by design) to leave. Their UX was one of the worst I've ever experienced in my life and they were consistently moving things around to make it worse. They essentially trap you, and someone without either the savvy or diligence will just give up.

Re: FTC takes action against GoDaddy for alleged lax data security

#95

Earlier quoted context omitted.

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

The whole thread is related to GoDaddy's numerous breaches not affecting their bottom line or market position. So it seems lots and lots and lots of people really don't care.

[deleted]

Re: FTC takes action against GoDaddy for alleged lax data security

#97

Earlier quoted context omitted.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data. If it can't hit the bottom line bigcorps don't care; liability is the only language they understand.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"

You have to provide your email to sign up for HN, however, it is not publicly visible. If YCombinator had to pay $10,000 for leaking a user email, this site isn't going to exist since it's not their core business and represents a huge liability.

It's also disproportionate. If my email is leaked in the context of receiving treatment for a stigmatized disease, that's a lot worse than an MMORPG leaking my real name.

Maybe some penalty is necessary but $10k or above per user is disproportionate for the vast majority of people. A $50/person penalty with gradations for sensitivity of the information is going to work better in practice. If leaking an SSN is more expensive than an email or site-specific ID, corporations might stop using SSNs to identify people to reduce their exposure

Re: FTC takes action against GoDaddy for alleged lax data security

#98

Earlier quoted context omitted.

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

Many people consider building a business on customer trust to be a strategic mistake.

Re: FTC takes action against GoDaddy for alleged lax data security

#99

I can't believe GoDaddy is still in business. Shows you can be a horrible company -- borderline scammy back in the day -- and somehow survive. FWIW we've used Gandi for years and very happy with it.

Marketing and large captive audience.

Re: FTC takes action against GoDaddy for alleged lax data security

#100

Earlier quoted context omitted.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data. If it can't hit the bottom line bigcorps don't care; liability is the only language they understand.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"

> Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"

You phrasing it like this is not a substitute for explaining why it wouldn't be those things.

Also, the most obvious thing is: if you're a healthcare provider, you would probably hire some hackers to go after your competition, and let heavy-handed fines take them down. Much easier than providing better value.

Post reply on HN