Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

161–170 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#161
post #132
post #109

Earlier quoted context omitted.

Not even that. You always have insurance for this stuff.

But then the insurance company has to pay, and they'll work hard to make sure it doesn't happen. This doesn't sound like an explanation to me.

You don't really have a choice, you have to have insurance for breaches (HIPAA term, not strictly the typical cybersec term, means any loss of control of information that results in potential of dissemination of PII).

Re: FTC takes action against GoDaddy for alleged lax data security

#162

Earlier quoted context omitted.

I think customers feel, rightly or wrongly, there's no alternative to CrowdStrike. There are so many alternatives to what GoDaddy provides, it is quite commoditized. But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...

I always feel dumb and like I'm missing some fundamental principle thinking about companies like GoDaddy. They provide a pretty undifferentiated commodity with a relatively low bar to switching, don't seem particularly well run or trustworthy based among other things on events like this, and their brand and marketing give off a vaguely skeezy low-rent vibe. Is it just a perpetual motion machine of market sharing affo…

> Is it just a perpetual motion machine of market sharing affording good marketing which then drives continued market share?

Worse. It's a market where most of the customers are unsophisticated but price sensitive, so they tend to prefer the provider with the lowest apparent price, and then the big providers compete on the basis of who can present the lowest apparent price through the use of dark patters, misleading claims, bait and switch tactics and hidden fees.

Example: GoDaddy provides a "free" site builder but if you use it the resulting site can't easily be extricated from their service and now you're locked in if you don't want to recreate your site. Meanwhile the price you were quoted for various services was an onboarding price and now that you've sunk a lot of time creating and improving the site you can't move, the price is going up.

This is, incidentally, a major reason WordPress is so popular despite being fairly miserable. It makes it easy for unsophisticated users to get started and your site isn't tied to a particular host.

Re: FTC takes action against GoDaddy for alleged lax data security

#164
post #97

Earlier quoted context omitted.

So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"

You have to provide your email to sign up for HN, however, it is not publicly visible. If YCombinator had to pay $10,000 for leaking a user email, this site isn't going to exist since it's not their core business and represents a huge liability. It's also disproportionate. If my email is leaked in the context of receiving treatment for a stigmatized disease, that's a lot worse than an MMORPG leaking my real name. May…

Have the C-suite hand back their compensation above minimum wage for the last 3 years. Fine the company, all profits, or a percentage of global revenue (and pay that back to customers).

If the outcome of ignoring data security is to not make any money then companies will actually do something about it.

Penalities should push the company to the point of failing.

Re: FTC takes action against GoDaddy for alleged lax data security

#165
post #68
post #58

Earlier quoted context omitted.

Then link it unedited. He's an asshole, I get it. But half of what is said about him is false (pee pee tapes?) that Americans don't give a darn about what is true.

Stop asking people to do unpaid labor for you.

Asking for citations of dubious claims is not asking for unpaid labor.

The reasonable reaction to a dubious unsupported claim is immediate out-of-hand dismissal. In asking for a citation, they are giving you the benefit of the doubt; i.e. doing you a favor.

Re: FTC takes action against GoDaddy for alleged lax data security

#166

Earlier quoted context omitted.

What guardrails are you talking about? Even ignoring the presidential immunity ruling that explicitly makes him Fuhrer, if Trump has ICE arrest all brown people tomorrow, what exactly is going to stop him? The courts? A judge can say whatever the hell they want from their bench, it won't stop an ICE agent from physically forcing you onto a C130 and taking you wherever. Trump already "deported" legal american citizens…

10% from each party support deporting legal immigrants.

Source?

Re: FTC takes action against GoDaddy for alleged lax data security

#167

Earlier quoted context omitted.

> Then you get people on HN shouting "regulatory capture!" and "stifling innovation!" You phrasing it like this is not a substitute for explaining why it wouldn't be those things. Also, the most obvious thing is: if you're a healthcare provider, you would probably hire some hackers to go after your competition, and let heavy-handed fines take them down. Much easier than providing better value.

Wouldn't that strongly incentivize companies to secure their data better, thereby achieving the goal?

It might achieve that goal, at the too-high expense of other things.

Re: FTC takes action against GoDaddy for alleged lax data security

#168
They should be looking into them for buying up all the competitors in domain selling. The bought two of the biggest competitors Dan.com and unregistery. Dan.com charge 9% on a sale of a domain now godaddy is charging 30%. Completely different company since Bob Parsons sold to a couple private equity firms.

Re: FTC takes action against GoDaddy for alleged lax data security

#169
post #79

Earlier quoted context omitted.

Using bogus whois info is a great way to lose your domain. If you are afraid of exposing your phone number and address, rent a P.O. box and get a throwaway number to use in the interim.

How does this happen? I have a few throwaway domains on bogus whois info. How would they find out and wouldn't you get a chance to fix it?

Yes, you will receive a warning first, at worst your domain will go into reconciliation.

Re: FTC takes action against GoDaddy for alleged lax data security

#170
post #155
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

I'd be less amazed if people could articulate why this matters. What is the harm being done here and why is it more costly than GoDaddy raising their prices by a few dollars?

One example: They're selling domain registration privacy, but don't sufficiently secure the private data. The entire Domains by Proxy dataset is available on the dark web.
Post reply on HN