5 ms·
With the GDPR, this is not just a security vulnerability. Is a law violation as not doing best efforts to protect customer private information.
by cientifico 8y ago
With the GDPR, this is not just a security vulnerability. Is a law violation as not doing best efforts to protect customer private information.
- throwawaymath 8y agoI don't think this is a GDPR violation or a security vulnerability. The purview of GDPR is personally identifiable information, whereas these are vulnerability details and passwords. If companies were storing their user lists in Trello boards that might be a bit different, but the examples in this blog post do not seem to be related to user data. They are also being volunteered by the companies using Trello, not Trello itself, so a potential violation would probably be levying fees against individual companies. It also doesn't strike me as a security vulnerability because it's not a technical failure in Trello's software. This is closer to accidentally publishing AWS keys on Github or opening a phishing email, and in neither case would GitHub or (say) Gmail be responsible for that. There are proactive steps they can take to mitigate this kind of mistake (as GitHub and Gmail do), and it's arguable Trello should do the same, but it doesn't seem like a compliance or security failure whatsoever.
- seanhunter 8y agoAlthough PII is dealt with in GDPR, GDPR doesn't only cover PII, and it makes numerous references to the obligation on anybody who processes personal data (not just PII) with respect to security. For example "Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing."
- cientifico 8y agoThe post talk also about CRM systems. And personal data also applied to employee data, or your partners data.