5 ms·
I think this is one of the best sets of responses to a security incident I've seen: 1. Disclose the incident ASAP, even before all facts are known. The disclos
by arciini 7y ago
I think this is one of the best sets of responses to a security incident I've seen:
1. Disclose the incident ASAP, even before all facts are known. The disclosure doesn't need to have any action items, and in this case, didn't
2. Add more details as investigation proceeds, even before it fully finishes to help clarify scope
The proactive communication and transparency could have downsides (causing undue panic), but I think these posts have presented a sense that they have it mostly under control. Of course, this is only possible because they, unlike some other companies, probably do have a good security team who caught this early.
I expect the next (or perhaps the 4th) post will be a fuller post-mortem from after the incident. This series of disclosures has given me more confidence in Stackoverflow than I had before!
- kaycebasques 7y agoI’m also impressed by the response. It also helps that the affected number of users is small, though. Imagine the same reporting, but the number of affected users was 1M. In other words, maybe good reporting can only get you so far.
- jkaplowitz 7y agoI've had the pleasure of working in an org led by Mary Ferguson (she's on the byline of these posts) at a previous employer. She's an excellent, honest, and caring leader who knows how to deal with people and improve the many interpersonal structures & systems. Bravo to her for continuing to kick ass in her current role.
- mandevil 7y agoOne major advantage SO has stems from its userbase: we are much less likely to panic than the typical user of a system not focused on software development.
- shay_ker 7y agoYou say that, but the second highest comment on the HN thread for the initial update was less than gracious: https://news.ycombinator.com/item?id=19936315 https://news.ycombinator.com/item?id=19936315
- brokenmachine 7y agoYou can please some of the people some of the time.
- nokya 7y agoI wish I could agree with you but the details provided in the post do not help us understand what happened. We only get very superficial information by one of the rare companies that could typically contribute and help the community by sharing what really went wrong. Right now, I'm in a situation that forces me to speculate (in addition to reading all the speculation comments below) on whether or not I could do the same mistake than SO did, and that terribly saddens me.
- jfoster 7y agoAt the bottom of the post it says: "We will provide more public information after our investigation cycle concludes." Might not be fair to judge the overall response yet. If full details of the problem were expected upon initial disclosure, then they wouldn't be able to do prompt disclosure.