5 ms·
I read him being very apologetic for their security shortcomings in all of the appropriate places, and only blaming delayed fixes on timing issues. He was very
by smokestack 16y ago
I read him being very apologetic for their security shortcomings in all of the appropriate places, and only blaming delayed fixes on timing issues. He was very contrite and forthcoming about their security issues. Accountability was all over the article.
- parfe 16y agoI disagree. Lucas names these children and attempts to personify them so blame can be shifted to the "bad guys" rather than his company. Lucas's post does not say "We screwed up." He says "We got screwed by Elliot." I'm saddened most because Lucas is not embarrassed to point out he was outwitted by children. When I foul up at my job I don't send an email detailing how some nasty client did something. I summarize what went wrong, how it should have been prevented and what steps I will be taking to prevent it in the future. I would never write an email: James Smith, a really evil customer (who happened to be working while there was thunder and lightning like Dr Frankenstein!), decided to try system("rm -fr /"). I knew it was possible, but I didn't feel like fixing it. Also I didn't feel like securing any of our other systems which explains those tweets, blog posts, DNS changes, and email compromises. I was lazy, but It's not my fault. gg, parfe P.S. Credit cards probably didn't get compromised. Tim the intern was the one who implemented the payment system and he had his own passwords set. (Note: I move this comment as I replied by mistake to CGamesPlay.)
- sangaya 16y agoDid you read the article? Lucas's post says: "This was really naive and irresponsible of me." That doesn't sound like he's shifting blame to me. You say: "I summarize what went wrong, how it should have been prevented and what steps I will be taking to prevent it in the future." The article is essentially just that, with one exception; they didn't list steps they "will be taking" to prevent it, they listed steps they have already taken in the last 3 days. As for Credit Card: "Credit cards – We have never stored credit cards on any PHP Fog server. There was never any possibility that credit cards could have been compromised by this attack."