Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

151–160 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#151

Earlier quoted context omitted.

I think customers feel, rightly or wrongly, there's no alternative to CrowdStrike. There are so many alternatives to what GoDaddy provides, it is quite commoditized. But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...

I always feel dumb and like I'm missing some fundamental principle thinking about companies like GoDaddy. They provide a pretty undifferentiated commodity with a relatively low bar to switching, don't seem particularly well run or trustworthy based among other things on events like this, and their brand and marketing give off a vaguely skeezy low-rent vibe. Is it just a perpetual motion machine of market sharing affo…

Are banks not fairly commodified too?

Did you move to a new bank after yours had a security breach?

There are so many breaches these days, companies don’t even have liability — any damages can be blamed on another breach.

Re: FTC takes action against GoDaddy for alleged lax data security

#152
post #128

Earlier quoted context omitted.

The whole thread is related to GoDaddy's numerous breaches not affecting their bottom line or market position. So it seems lots and lots and lots of people really don't care.

I can take my business elsewhere and do. but do I blame the average person for not caring? The kind of person who would use GoDaddy for hosting? I find it really hard to blame them.

Also your data will probably just be leaked somewhere else sometime anyway. Punishing a single company once unfortunately does next to nothing at this point.

Re: FTC takes action against GoDaddy for alleged lax data security

#153
GoDaddy is one of the sleaziest companies I know of.

I ran a website hosted on GoDaddy for a local business when the server cluster was hacked. GoDaddy admitted it was their fault, but the business ended up having to pay me to fix the site. GoDaddy also managed to convince the business to pay for an additional monthly "security" plan, which included page caching. They set everything up over the phone without talking to me at all.

The next day I notice some odd behavior with the admin pages, then realize they're being cached, not only that but they're now publicly accessible. GoDaddy's improved security plan ended up being responsible for a data leak. They really screwed up twice but there was zero penalty, the only consequence was they made more money. The business chose to stay with GoDaddy, despite my recommendations. They saw the ads on TV and were convinced GoDaddy is the pinnacle of web hosting.

Also, check this out: https://www.butterflyave.com/

Those assholes have parked my old business name, and want to sell it back to me for $1,499.

Re: FTC takes action against GoDaddy for alleged lax data security

#155
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

I'd be less amazed if people could articulate why this matters. What is the harm being done here and why is it more costly than GoDaddy raising their prices by a few dollars?

Re: FTC takes action against GoDaddy for alleged lax data security

#156

Earlier quoted context omitted.

I always feel dumb and like I'm missing some fundamental principle thinking about companies like GoDaddy. They provide a pretty undifferentiated commodity with a relatively low bar to switching, don't seem particularly well run or trustworthy based among other things on events like this, and their brand and marketing give off a vaguely skeezy low-rent vibe. Is it just a perpetual motion machine of market sharing affo…

Are banks not fairly commodified too? Did you move to a new bank after yours had a security breach? There are so many breaches these days, companies don’t even have liability — any damages can be blamed on another breach.

Not commodified as much as regulated. The personal data that banks collect is probably mandated by the government, so switching banks doesn't really change the risk someone faces. And probably a bunch of other things that would otherwise be competitive advantages for customers too. The lack of full reserve banks (or close enough too) despite what would be a reasonable level of customer demand, for example.

Re: FTC takes action against GoDaddy for alleged lax data security

#157

GoDaddy is one of the sleaziest companies I know of. I ran a website hosted on GoDaddy for a local business when the server cluster was hacked. GoDaddy admitted it was their fault, but the business ended up having to pay me to fix the site. GoDaddy also managed to convince the business to pay for an additional monthly "security" plan, which included page caching. They set everything up over the phone without talking…

They seem to park so many domains it wouldn't surprise me if they park new domains based on domain searches. There is a clear motivation there so I always run whois in the terminal instead of searching on any domain registrar with the exception of cloud providers who don't make much of their money from domains.

Re: FTC takes action against GoDaddy for alleged lax data security

#158
post #79

Earlier quoted context omitted.

Update your whois to bogus information, transfer the domain, restore whois information. Cloudflare is the cheapest domain registrar long-term, you might get cheaper ones for the first year or first 3 years.

Using bogus whois info is a great way to lose your domain. If you are afraid of exposing your phone number and address, rent a P.O. box and get a throwaway number to use in the interim.

How does this happen? I have a few throwaway domains on bogus whois info. How would they find out and wouldn't you get a chance to fix it?

Re: FTC takes action against GoDaddy for alleged lax data security

#159
post #121

Earlier quoted context omitted.

The big four (CRWD, S1, Prisma, and MDE) all mostly comparable tbh. EDR (especially Windows EDR) is heavily commodified.

A commodified market with no good product? Something is wrong here.

It's enterprise software. The people using the software and the people choosing the software are not the same people. In many cases they only buy it to satisfy a contractual or regulatory requirement and then the primary criterion is which one costs less or which one's sales reps give the best kickbacks, with considerations like "is it any good" not really playing a major role.

Re: FTC takes action against GoDaddy for alleged lax data security

#160
post #16

I was shocked when I purchased a domain recently on GoDaddy (I normally use Cloudflare or AWS) and noticed that they have an 'upsell' with more security options (MFA and some other features) for something like $10/yr. Why wouldn't they want their customers to be more secure by default? To me it just reeks of money-grabbing for people that are none the wiser.

Why did you purchase a domain on GoDaddy if you know better?
Post reply on HN