3 ms·
Another breach. Credit where credit is due, they haven’t done too badly with the announcement, but there are some key facts that people would like to know that
by graystevens 9y ago
Another breach. Credit where credit is due, they haven’t done too badly with the announcement, but there are some key facts that people would like to know that they unfortunately haven’t mentioned.
* They became aware of it Dec 11th – do they have an estimate of when this occurred?
* They mention what types of information has likely been affected, yet for some reason they mention “no payment details have been breached” right at the end of the Q&A? I’d have expected that to be much higher up the announcement.
* Not needed in the general announcement, but knowing how is always a point of interest (that may just be me, being in the business) – third party? SQLi? etc.
* How did they become aware of this? Did they discover this internally? Or did an outsider give them the heads up.
I’d like to think that one day, that last question can be answered by my startup[0], detecting breaches with a high degree of confidence with pseudo/honey users.
[0] https://breachinsider.com https://breachinsider.com