Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

111–120 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#111
SendGrid, pre IPO, had a GoDaddy security incident: someone social engineered one of the GoDaddy support reps into giving them control of our domain. We were able to re-secure the domain before the attacker fully locked us out. They could have powned all of our email links.

Re: FTC takes action against GoDaddy for alleged lax data security

#112
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

I've had a dim view of them ever since my first interaction with Domains by Proxy (At the time, I recall finding that many 'windows support' scam sites and other malware distribution was showing up under their domains, and every attempt to uncover would only lead to a 'oh that account is now banned but we wont tell you thx'.)

... Honestly it reminds me of how some Internet VOIP providers won't tell the name of the business who actually bought the number (Which, of course, complicates the ability to collect on TCPA when it's a number used for spam.)

Re: FTC takes action against GoDaddy for alleged lax data security

#113
post #91

Earlier quoted context omitted.

I think customers feel, rightly or wrongly, there's no alternative to CrowdStrike. There are so many alternatives to what GoDaddy provides, it is quite commoditized. But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...

I've actually not worked anywhere that has used CrowdStrike. It's usually ruled out as too expensive (I've mostly worked in public sector). I've had very good experiences with Sentinel One and Microsoft Defender. I've had terrible experiences with Trellix and Sophos."Oopsy" aside, is CrowdStrike really that much better than the competition?

I only worked at one shop that used CrowdStrike but TBH compared to the others I've had to deal with, definitely is the 'least' shitty compared to other competitors...

Re: FTC takes action against GoDaddy for alleged lax data security

#114

If you think GoDaddy is the most terrible, you have never been exposed to the hell that is Network Solutions. GoDaddy is big, safe and terrible. Network Solutions is big, safe and even worse.

I can't believe they still exist. I remember having to fax my changes to them, pre-2000, when they were the only game in house.

Crazy.

Re: FTC takes action against GoDaddy for alleged lax data security

#115

I can't believe GoDaddy is still in business. Shows you can be a horrible company -- borderline scammy back in the day -- and somehow survive. FWIW we've used Gandi for years and very happy with it.

I used Gandi for a long time and switched after they were bought out and registration prices started rising. HN article from 2023 - https://news.ycombinator.com/item?id=35080777

After that I've used spaceship.com, NameCheap's rebrand, without complaint and most recently porkbun.com due to support in dnscontrol.

Re: FTC takes action against GoDaddy for alleged lax data security

#116

Earlier quoted context omitted.

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

[flagged]

It's a bit exhausting that every time anyone says anything about executives in any context, we have to make sure to bring up the cold-blooded murder of one of them and make sure to remind everyone that some people on the internet think that that murder was justified.

It's free internet points, I guess, but it's also not constructive and frankly more than a little bit creepy.

Re: FTC takes action against GoDaddy for alleged lax data security

#117

If you think GoDaddy is the most terrible, you have never been exposed to the hell that is Network Solutions. GoDaddy is big, safe and terrible. Network Solutions is big, safe and even worse.

Years ago, before I was very computer literate, my friend turned me onto Network Solutions for hosting.

Long story short I got locked out of my account. It truly seemed like the support didn't want to help me get back in. This went for what felt like forever but was probably just a few weeks. I never got a resolution and was never able to log back in to my account.

I eventually did a chargeback because I couldn't use a service that I was paying for. They were all of a sudden proactive about reaching out - with an accusatory email nonetheless. In their view, the chargeback was fraudulent.

Re: FTC takes action against GoDaddy for alleged lax data security

#118

Earlier quoted context omitted.

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

Yeah I got those trainings when I was merely healthcare adjacent adjacent adjacent.

Re: FTC takes action against GoDaddy for alleged lax data security

#119

Earlier quoted context omitted.

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

It turns out HIPAA is a pretty good incentive to do the right thing, and the key difference is that there are actual consequences for violating HIPAA.

Even better, the consequences are stronger in the event that the company obviously wasn't giving a fuck about security.

I wish we had HIPAA for all PII.

Re: FTC takes action against GoDaddy for alleged lax data security

#120
post #54

Earlier quoted context omitted.

Crowdstrike took down all windows boxes that had their software installed and didn’t really affect them.

I think customers feel, rightly or wrongly, there's no alternative to CrowdStrike. There are so many alternatives to what GoDaddy provides, it is quite commoditized. But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...

I always feel dumb and like I'm missing some fundamental principle thinking about companies like GoDaddy. They provide a pretty undifferentiated commodity with a relatively low bar to switching, don't seem particularly well run or trustworthy based among other things on events like this, and their brand and marketing give off a vaguely skeezy low-rent vibe. Is it just a perpetual motion machine of market sharing affording good marketing which then drives continued market share?
Post reply on HN