Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

121–130 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#121
post #91

Earlier quoted context omitted.

I've actually not worked anywhere that has used CrowdStrike. It's usually ruled out as too expensive (I've mostly worked in public sector). I've had very good experiences with Sentinel One and Microsoft Defender. I've had terrible experiences with Trellix and Sophos."Oopsy" aside, is CrowdStrike really that much better than the competition?

The big four (CRWD, S1, Prisma, and MDE) all mostly comparable tbh. EDR (especially Windows EDR) is heavily commodified.

A commodified market with no good product? Something is wrong here.

Re: FTC takes action against GoDaddy for alleged lax data security

#122

Earlier quoted context omitted.

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

It turns out HIPAA is a pretty good incentive to do the right thing, and the key difference is that there are actual consequences for violating HIPAA. Even better, the consequences are stronger in the event that the company obviously wasn't giving a fuck about security. I wish we had HIPAA for all PII.

But it does slow things down. Startups don't want to deal with that stuff. So they'd have to outsource it. I'm not sure how.

Re: FTC takes action against GoDaddy for alleged lax data security

#123

Earlier quoted context omitted.

[flagged]

It's a bit exhausting that every time anyone says anything about executives in any context, we have to make sure to bring up the cold-blooded murder of one of them and make sure to remind everyone that some people on the internet think that that murder was justified. It's free internet points, I guess, but it's also not constructive and frankly more than a little bit creepy.

It's the time we live in.

Re: FTC takes action against GoDaddy for alleged lax data security

#124
post #27
post #15

Earlier quoted context omitted.

Change "gone" to "out of power," if you like. The FTC Chair controls the agency's agenda, and the Chair switched parties last week.

The new chair was nominated for the FTC (as a commissioner, not chair) by Biden.

By law the FTC, like the FCC, cannot have more than 3 commissioners from the same party.

When there is an opening and there are already 3 from the President's party traditionally the President asks the Senate leader of the other party who should be nominated and the Senators of the President's party do not vote against that nominee.

Re: FTC takes action against GoDaddy for alleged lax data security

#125
post #61

Earlier quoted context omitted.

Not the person you are replying to, but I work in security and have spent ~5 years of my career helping various companies set up and maintain security awareness programs. There are some out-of-the-box solutions that can start you on your way to creating a security awareness training program, such as KnowBe4 and ProofPoint (there are others as well, but these are some of the big names). If you don't have in-house secu…

As a technically-minded person, I've found both KnowBe4 and ProofPoint trainings to be very lacking/boring/superficial.

KnowBe4 is awesome. It trains everyone to be on the lookout. The penalty for barely screwing up is another boring training session that no one has time for. Very painful. Pain is a great teacher.

Re: FTC takes action against GoDaddy for alleged lax data security

#126
post #101

If you think GoDaddy is the most terrible, you have never been exposed to the hell that is Network Solutions. GoDaddy is big, safe and terrible. Network Solutions is big, safe and even worse.

I can't pass by this comment about Network Solutions without an enthusiastic second. Several times per month I help various customers with their domains, and when I see that one is with Network Solutions, I know I'm going to have to waste a bunch of time with their terrible DNS editor and will have to wait around for at least 20 minutes before their own editor reflects the changes I've made. The worst part is that wh…

You just brought back a fifteen year old memory. I have used a lot of hosting services but have always avoided GoDaddy. The name sounded too playful...and that was after being a Host Gator customer for years. They were decent back in the day and let me serve rediculous amounts of data from a shared hosting tier that always performed well...I was probably the noisy neighbor.

Re: FTC takes action against GoDaddy for alleged lax data security

#128

Earlier quoted context omitted.

> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.

The whole thread is related to GoDaddy's numerous breaches not affecting their bottom line or market position. So it seems lots and lots and lots of people really don't care.

I can take my business elsewhere and do.

but do I blame the average person for not caring? The kind of person who would use GoDaddy for hosting? I find it really hard to blame them.

Re: FTC takes action against GoDaddy for alleged lax data security

#129
post #5

It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…

>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…

We’Ve eVaLuaTeD the RisKs

Re: FTC takes action against GoDaddy for alleged lax data security

#130

Earlier quoted context omitted.

Luckily we have enough remaining guardrails that it's unlikely to happen within the next 4 years. But we're getting closer, that's for sure. And the Supreme Court's disastrous decision on presidential immunity is allowing Trump to play Generalissimo.

What guardrails are you talking about? Even ignoring the presidential immunity ruling that explicitly makes him Fuhrer, if Trump has ICE arrest all brown people tomorrow, what exactly is going to stop him? The courts? A judge can say whatever the hell they want from their bench, it won't stop an ICE agent from physically forcing you onto a C130 and taking you wherever. Trump already "deported" legal american citizens…

10% from each party support deporting legal immigrants.
Post reply on HN