4 ms·
You have to evaluate the type of account disclosure that was possible against your own use cases. My company bills 1m a day through our online site, if my logi
by robalfonso 10y ago
You have to evaluate the type of account disclosure that was possible against your own use cases.
My company bills 1m a day through our online site, if my logins to our domain registrar were exposed then yes. .00001 is worth it, in the case someone would gain access and change our dns or do something else nefarious.
Like wise if my login to this site was disclosed, I can live with cleaning that up should it get out.
What shouldn't happen is the companies who were affected or the company who caused this (cloudflare) to say "no big deal"
At the very least they should say if you potentially used a serious service during this time and that service was using cloudflare then you might consider changing for reasons X,Y,Z.
- 794CD01 10y ago>You have to evaluate the type of account disclosure that was possible against your own use cases. Exactly. Evaluating risk levels and weighing tradeoffs accurately is taking security seriously. Overreacting to insanely unlikely scenarios is not.
- robalfonso 10y agoYes, but you might not understand me. I meant they are assuming they are doing the evaluating on behalf of their customers. I'm the customer and I've got to do the evaluating , but I might not understand the potential but telling me there is almost no issue doesn't help me do that.
- 794CD01 10y agoIf they understand security better than their customers, it's correct for them to say so when an issue doesn't require customers to individually review whether they are affected. If they misjudge that, it isn't an indication that they don't "take security seriously". It just means they made an error in judgment.