12 ms·
This smells like someone leaving a DB open to the world (remember the old MongoDB open by default?) I think stealing a whole database raises very serious quest
by avitzurel 8y ago
This smells like someone leaving a DB open to the world (remember the old MongoDB open by default?)
I think stealing a whole database raises very serious questions as to how technically this was done and how would you prevent this at your company.
Unfortunately "transparency first" aside, companies don't usually release this information which leaves us all wondering how we can better protect our users (outside of having sane defaults, closed by default, no ssh, private networks etc...).
- thefounder 8y agoYou would be surprised to find out how many large companies(i.e top 500) lost theier databases, banks included. Many can be googled but most never made it public or didn't even know what happened to them. Chances are that your contact data has been leaked by several parties already. My conclusion is that you can't secure data unless you make a goal of that and even then it's not a sure thing. All your private networks have multiple public entery points and possibly a coordinator(i.e kubernetes admin). Most ecommerce companies and even payment processing companies think of security as an accessory to their business not a primary concern. If they are too focused on security they loose market share(i.e the vetting takes too much time) The only solution is to consider all unencrypted data public and use encryption at the client level(i.e mobile device).
- fogetti 8y agoThat's why the EU introduced GDPR. So you are legally responsible (and the fines can be pretty steep) if you 'forget' to make the breach public.