4 ms·
> In the hours that followed, RSA’s executives debated how to go public. One person in legal suggested they didn’t actually need to tell their customers, Sam Cu
by ddlatham 5y ago
> In the hours that followed, RSA’s executives debated how to go public. One person in legal suggested they didn’t actually need to tell their customers, Sam Curry remembers. Coviello slammed a fist on the table: They would not only admit to the breach, he insisted, but get on the phone with every single customer to discuss how those companies could protect themselves. Joe Tucci, the CEO of parent company EMC, quickly suggested they bite the bullet and replace all 40 million-plus SecurID tokens. But RSA didn’t have nearly that many tokens available—in fact, the breach would force it to shut down manufacturing. For weeks after the hack, the company would only be able to restart production in a diminished capacity.
> As the recovery effort got under way, one executive suggested they call it Project Phoenix. Coviello immediately nixed the name. “Bullshit,” he remembers saying. “We're not rising from the ashes. We're going to call this project Apollo 13. We're going to land the ship without injury.”
This is the sort of response that would increase my trust to choose this company in the future. This is not easy. Our human instincts naturally kick in to minimize our faults and protect ourselves. Choosing to put the customer first at risk of your own reputation is hard, but the right choice, even for your reputation in the end.
- YetAnotherNick 5y agoI don't know the contract with clients or anything but "didn’t actually need to tell their customers" seems totally illegal to me if the RSA is the provider of one of the most fundamental layer of security to large companies. It is a PR piece. Not saying that RSA likely did the best they could do to be secured from the hack, but this story is a pr piece.
- m463 5y agoThere's plenty of examples supporting that. The earliest I remember was the Tylenol murders where 31 million bottles of tylenol were taken off the shelves: https://en.wikipedia.org/wiki/Tylenol_(brand)#1982_Chicago_Tylenol_murders https://en.wikipedia.org/wiki/Tylenol_(brand)#1982_Chicago_T... In the end, their brand got stronger and more trustworthy. (and I believe we got sealed bottles)
- cafard 5y agoTamper-proof. Yes, that was the example that occurred to me.
- beambot 5y agoLooks like Tylenol is/was owned by J&J... the same company that knowingly sold talcum powder that caused cancer: https://www.npr.org/2020/05/19/859182015/johnson-johnson-stops-selling-talc-based-baby-powder-in-u-s-and-canada https://www.npr.org/2020/05/19/859182015/johnson-johnson-sto...
- nix23 5y agoJust imagine you knowingly let parent threat their baby's with asbestos...and what happened? Nothing https://www.cancer.org/cancer/cancer-causes/talcum-powder-and-cancer.html https://www.cancer.org/cancer/cancer-causes/talcum-powder-an...
- TheManInThePub 5y ago> sold talcum powder that caused cancer Ummm Your link contained no evidence for this. A search of the NHS website also suggests no clear evidence [1]. Cancer Research (a respected UK charity) give a layman's summary (albeit focusing on ovarian cancer), stating no clear evidence and pointing out that there are far more serious risks to worry about [2]. [1] https://www.evidence.nhs.uk/search?om=[{%22ety%22:[%22Information%20for%20the%20Public%22]}]&q=talcum+powder+cancer&sp=on https://www.evidence.nhs.uk/search?om=[{%22ety%22:[%22Inform... [2] https://www.cancerresearchuk.org/about-cancer/causes-of-cancer/cosmetics-and-toiletries https://www.cancerresearchuk.org/about-cancer/causes-of-canc...