Live data from Hacker News

FTC takes action against GoDaddy for alleged lax data security

ftc.gov

171–180 of 181 posts

Re: FTC takes action against GoDaddy for alleged lax data security

#171
post #54

Earlier quoted context omitted.

Crowdstrike took down all windows boxes that had their software installed and didn’t really affect them.

Crowdstrike's security reputation matters a lot more. I'll bet the customers assume the competitors have the same reliability problems, they can tolerate a little downtime, and going with nobody is even worse.

> they can tolerate a little downtime

A couple of days of production stopped can cost a lot of money.

Re: FTC takes action against GoDaddy for alleged lax data security

#172
post #121

Earlier quoted context omitted.

The big four (CRWD, S1, Prisma, and MDE) all mostly comparable tbh. EDR (especially Windows EDR) is heavily commodified.

A commodified market with no good product? Something is wrong here.

Race to the bottom.

Re: FTC takes action against GoDaddy for alleged lax data security

#173
post #165
post #68

Earlier quoted context omitted.

Stop asking people to do unpaid labor for you.

Asking for citations of dubious claims is not asking for unpaid labor. The reasonable reaction to a dubious unsupported claim is immediate out-of-hand dismissal. In asking for a citation, they are giving you the benefit of the doubt ; i.e. doing you a favor .

Where are the "dubious" claims? No one's saying he's an alien or playing 4-D chess.

He's one of the most public figures in the world right now, with hours of video "evidence" widely and easily available. Asking someone to prove he did an obvious thing in public is demanding unpaid labor.

This is not the same as expecting someone to back up a claim of a homeopathic treatment for brain cancer.

Re: FTC takes action against GoDaddy for alleged lax data security

#174
post #157

GoDaddy is one of the sleaziest companies I know of. I ran a website hosted on GoDaddy for a local business when the server cluster was hacked. GoDaddy admitted it was their fault, but the business ended up having to pay me to fix the site. GoDaddy also managed to convince the business to pay for an additional monthly "security" plan, which included page caching. They set everything up over the phone without talking…

They seem to park so many domains it wouldn't surprise me if they park new domains based on domain searches. There is a clear motivation there so I always run whois in the terminal instead of searching on any domain registrar with the exception of cloud providers who don't make much of their money from domains.

I've definitely heard stories of people saying GoDaddy grabbed their domain right after they searched it. There's almost always someone following those stories saying that it was just coincidental.

I have zero trust in GoDaddy. I remember when I was kid using their service because my grandparents had bought a website and hosting services through them and they wanted me to create the site. Their interface was so confusing and I felt like I suddenly had no understanding of how computers work.

Fast forward to today, and yes, past me was not very knowledgeable, but not to the degree their site made me feel. They use custom terminology for industry standard things, group things together in weird locations, and have so many dark patterns.

My point: sleazy tactics like domain front-running would honestly be on brand. I tell people not to use GoDaddy and definitely not for domain searching.

Re: FTC takes action against GoDaddy for alleged lax data security

#175
post #61

Earlier quoted context omitted.

Not the person you are replying to, but I work in security and have spent ~5 years of my career helping various companies set up and maintain security awareness programs. There are some out-of-the-box solutions that can start you on your way to creating a security awareness training program, such as KnowBe4 and ProofPoint (there are others as well, but these are some of the big names). If you don't have in-house secu…

As a technically-minded person, I've found both KnowBe4 and ProofPoint trainings to be very lacking/boring/superficial.

Very glad to these options and how they can be perceived by people, this should mean there are paths and that if they can be made better / different for different audiences that they may be well received.

Appreciate you and @ziddoap offering insight!

Looking at starting deck for FTC issues, Hipaa issues, and Google's policies - all for websites and apps specifically very soon and let the videos / webinars / interactive / discussions grow from here.

Re: FTC takes action against GoDaddy for alleged lax data security

#177

Earlier quoted context omitted.

As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.

Except Change Healthcare got hacked, lost a ton of records and they are still operating. So those fines must be, could be up to xx,000 per person affected but in actuality, those affected will get Arbys coupon and C Suite will lose a week of yacht time.

I'd honestly prefer an Arby's coupon or perhaps a crisp $1 note over "1 year subscription to our credit monitoring service"

Re: FTC takes action against GoDaddy for alleged lax data security

#180
Firstly, I would say spyrecovery36 @ gm ail com is the only hacker you can go to for positive outcome here. Customer service is great. After reading great reviews about him on almost all the websites i researched on, I hired him to hack my cheating spouse's iPhone 14 and trust me when i say he hacked the device and gave me full access to his phone. His services were cost effective, top notch and easy to use. I highly recommend this hacker for any hacking services. Pay for the use of his services and avoid scam stories. stay safe
Post reply on HN