Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

101–110 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#101

If you think GoDaddy is the most terrible, you have never been exposed to the hell that is Network Solutions. GoDaddy is big, safe and terrible. Network Solutions is big, safe and even worse.

I can't pass by this comment about Network Solutions without an enthusiastic second. Several times per month I help various customers with their domains, and when I see that one is with Network Solutions, I know I'm going to have to waste a bunch of time with their terrible DNS editor and will have to wait around for at least 20 minutes before their own editor reflects the changes I've made.

The worst part is that when replacing an A record with a CNAME, it lets you delete the A record but then blocks you from adding the CNAME, because "a record with that name already exists" (referring to the one that was just deleted). This is where the 20+ minute wait changes from "inconvenient" to "downtime". It's been like this for at least 15 years.

Re: FTC takes action against GoDaddy for alleged lax data security

#102
post #79

Earlier quoted context omitted.

Update your whois to bogus information, transfer the domain, restore whois information. Cloudflare is the cheapest domain registrar long-term, you might get cheaper ones for the first year or first 3 years.

Using bogus whois info is a great way to lose your domain. If you are afraid of exposing your phone number and address, rent a P.O. box and get a throwaway number to use in the interim.

You will not lose your domain for having bogus information for 7 days. Having bogus information takes months of not an entire year to ever go through and the worst you will possibly get is a very stern warning to update your information or your domain will be taken away.

I still have a .com domain that I've registered from when I was a child and I've just never bothered to update the information on it, the regulations on these are as lax as godaddys security.

If you're a site with millions of views a day this might be different.

Re: FTC takes action against GoDaddy for alleged lax data security

#103
post #54

Earlier quoted context omitted.

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

Crowdstrike took down all windows boxes that had their software installed and didn’t really affect them.

Yet.

it takes time there are plenty of lawsuits flying around that incident .

Even if they win all the suits without settling or loosing, customers will negotiate far stiffer penalties and controls on next renewal or get steep discounts or just straight up switch vendors .

Sooner or later their ability to be competitive will get affected and they will likely become a target for acquisition and rebranding.

Organizations of that magnitude do not collapse overnight like startups

Re: FTC takes action against GoDaddy for alleged lax data security

#104
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

True story.

I worked for a medium sized company. They had a very large commercial e-commerce site for their customers. They used Wordpress sites that were hosted on GoDaddy. I worked there for two years. They never updated any of their passwords for GoDaddy or their Wordpress sites.

Its been almost ten years since I've worked there and I occasionally log on just to see if they've updated anything. Nope. Last time I checked was early 2024. Still nothing was updated.

I mean, someone gets access to their GoDaddy account and within minutes will have full control of a major bit of their business. Talk about playing with fire.

Re: FTC takes action against GoDaddy for alleged lax data security

#105
post #80

Earlier quoted context omitted.

An unofficial ranking of the most NSFW GoDaddy commercials ever: https://www.golfdigest.com/story/an-unofficial-ranking-of-th... The Woman(!) Behind GoDaddy's Tasteless, Effective Super Bowl Ads: https://www.forbes.com/sites/jeffbercovici/2013/02/06/the-wo... Who Let These Commercials Be On TV? https://www.youtube.com/watch?v=_rRopnyZaR0 GoDaddy's most infamous ads: https://www.youtube.com/watch?v=u7yFCqOAb9Y 10 SEXI…

Hilarious to see all the takedowns on these videos. Who the hell DMCA's a reposted advertisement? It's literally free advertising. The only reason they would take these down is because they were ashamed of them - and they probably should be.

To be fair, they should also have a site gaydaddy.com and tv commercials that objectify sexy men.

Re: FTC takes action against GoDaddy for alleged lax data security

#106
post #54

Earlier quoted context omitted.

Crowdstrike took down all windows boxes that had their software installed and didn’t really affect them.

Yet. it takes time there are plenty of lawsuits flying around that incident . Even if they win all the suits without settling or loosing, customers will negotiate far stiffer penalties and controls on next renewal or get steep discounts or just straight up switch vendors . Sooner or later their ability to be competitive will get affected and they will likely become a target for acquisition and rebranding. Organizatio…

I’ve been around long enough to see this not happen. Crowdstrike ticks a lot of boxes and no one buys them for anything else.

Re: FTC takes action against GoDaddy for alleged lax data security

#108
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

[flagged]

Re: FTC takes action against GoDaddy for alleged lax data security

#109

Earlier quoted context omitted.

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

Except Change Healthcare got hacked, lost a ton of records and they are still operating. So those fines must be, could be up to xx,000 per person affected but in actuality, those affected will get Arbys coupon and C Suite will lose a week of yacht time.

Not even that. You always have insurance for this stuff.

Re: FTC takes action against GoDaddy for alleged lax data security

#110

In related news, their ISO 27001 certificate just expired. Seems in line with their overall security posture then https://img1.wsimg.com//Sitecore/6/1/registrar-iso27001-cert...

ISO 27001 doesn’t mean secure. It does mean they have invested money in compliance though.
Post reply on HN