Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

141–150 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#141
The FTC action is because GoDaddy claimed to have security when they didn’t - not because they didn’t have security in the first place.

Subtle but important difference.

Also the remedies include having a complete security program within 90 days IIRC, on what world would anyone think that’s remotely possible?

They wouldn’t even have an RFP drafted in 90 days.

Re: FTC takes action against GoDaddy for alleged lax data security

#142

A good law would be that if a customer's data is leaked, any and all revenue that was made with/through that customer must be returned to the customer. All of a sudden companies will magically remember how to do half-way sober IT again.

This would be awesome, few if any companies would be able to take the risk of storing customer info, since they would need very good security, and very good reason for every piece of data they store, and insurance to cover themselves in case they do lose your data. In fact companies would go out of their way to not store any of your data.

Re: FTC takes action against GoDaddy for alleged lax data security

#143

Earlier quoted context omitted.

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

That reputational loss is almost exclusively among those who understand how the crowdstrike products work, but the Venn diagram with those folks and “people at companies who can approve large expenses” is nearly empty.

Yes, the CRWD ticker took a hard hit, dropping about 50% over the course of 2 weeks last July. But... it recently topped its previous high, only 7 months later (which is like 1/2 or 1/3 of an enterprise sales cycle!).

Re: FTC takes action against GoDaddy for alleged lax data security

#144

A good law would be that if a customer's data is leaked, any and all revenue that was made with/through that customer must be returned to the customer. All of a sudden companies will magically remember how to do half-way sober IT again.

This would be awesome, few if any companies would be able to take the risk of storing customer info, since they would need very good security, and very good reason for every piece of data they store, and insurance to cover themselves in case they do lose your data. In fact companies would go out of their way to not store any of your data.

> since they would need very good security

As someone with 20+ years experience in IT/DevOps/Cloud/whatever, I disagree.

They would simply need to actually use the security that is already there. Data leaks that happen due to lack of "very good security" are extremely rare. In almost every case, someone was doing something very stupid that everyone already agrees is a very obvious thing to not do.

.

> In fact companies would go out of their way to not store any of your data.

The companies that already use existing IT systems, as they are already designed to be used, have no problem protecting customer data and not leaking it. The companies that can not properly hire our outsource competent IT people shouldn't be storing data in the first place. Commerce is subject to regulation, due to human nature, and different regulation is needed today.

.

> and insurance to cover themselves in case they do lose your data

I would prefer that this kind of insurance not exist.

Re: FTC takes action against GoDaddy for alleged lax data security

#145
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

True story. I worked for a medium sized company. They had a very large commercial e-commerce site for their customers. They used Wordpress sites that were hosted on GoDaddy. I worked there for two years. They never updated any of their passwords for GoDaddy or their Wordpress sites. Its been almost ten years since I've worked there and I occasionally log on just to see if they've updated anything. Nope. Last time I c…

> Its been almost ten years since I've worked there and I occasionally log on just to see if they've updated anything. Nope. Last time I checked was early 2024. Still nothing was updated.

... but.. why?

Why let them live rent-free in your mind? Why admit to that in even a pseudonymous space?

Re: FTC takes action against GoDaddy for alleged lax data security

#146

Earlier quoted context omitted.

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

Except Change Healthcare got hacked, lost a ton of records and they are still operating. So those fines must be, could be up to xx,000 per person affected but in actuality, those affected will get Arbys coupon and C Suite will lose a week of yacht time.

I didn’t even get an Arby’s coupon.

I got a letter telling me they gave away my information with a link to an “identity monitoring” site that looks like the CEOs nephew built in a weekend and just errors out when I sign up.

Re: FTC takes action against GoDaddy for alleged lax data security

#147
post #16

I was shocked when I purchased a domain recently on GoDaddy (I normally use Cloudflare or AWS) and noticed that they have an 'upsell' with more security options (MFA and some other features) for something like $10/yr. Why wouldn't they want their customers to be more secure by default? To me it just reeks of money-grabbing for people that are none the wiser.

Not exactly the same but this reeks of https://sso.tax.

Re: FTC takes action against GoDaddy for alleged lax data security

#148

The FTC action is because GoDaddy claimed to have security when they didn’t - not because they didn’t have security in the first place. Subtle but important difference. Also the remedies include having a complete security program within 90 days IIRC, on what world would anyone think that’s remotely possible? They wouldn’t even have an RFP drafted in 90 days.

GoDaddy will have known of this investigation since it began—probably for years. So it’s 90 days from now(ish), but they (should) have gotten a head start.

Re: FTC takes action against GoDaddy for alleged lax data security

#150

Earlier quoted context omitted.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"

> Then you get people on HN shouting "regulatory capture!" and "stifling innovation!" You phrasing it like this is not a substitute for explaining why it wouldn't be those things. Also, the most obvious thing is: if you're a healthcare provider, you would probably hire some hackers to go after your competition, and let heavy-handed fines take them down. Much easier than providing better value.

Wouldn't that strongly incentivize companies to secure their data better, thereby achieving the goal?
Post reply on HN