3 ms·
I am not convinced that this was responsible behavior on the part of upguard. They discovered a breach, and apparently downloaded all the files. The report deta
by techslave 8y ago
I am not convinced that this was responsible behavior on the part of upguard. They discovered a breach, and apparently downloaded all the files. The report details the kinds of files and sample of the information in them.
If upguard's behavior were responsible, why would they have downloaded any more data than necessary to determine that it was sensitive stuff? They would have noticed it, reported it (without downloading) and perhaps helped fix it. I doubt very much that the OK Dept of Securities would have subsequently given them access to the files so as to do some kind of audit on sensitivity, in a non-NDA manner.
This post reads more like an ad for upguard than a responsible disclosure.
- dmix 8y agoPossibly but the sampled data they mentioned makes this seem 100x worse than just announcing "millions of files". This was a very very serious leak and I don't see how the severity could be communicated otherwise. > This post reads more like an ad for upguard than a responsible disclosure. As long as there is quality information in return I have no problem with this type of stuff appearing HN. And this was a very interesting post.
- krageon 8y agoKnowing a little bit about how government works, if they didn't have proof of what happened it is not unthinkable that they would close the immediate leak and then deny anything ever happened. Nobody would win in that case, because nobody competent actually verified that a fix was done. And nobody would know, either - it'd just be two parties denying the other's point of view.