3 ms·
Being wary of the guy, sure. But it's a terrible response in general. The correct response is to take the site down! Monitoring IP addresses? Really? First, it
by solveit 5y ago
Being wary of the guy, sure. But it's a terrible response in general. The correct response is to take the site down! Monitoring IP addresses? Really?
First, it's trivial to just use a different IP address. Second, even if you could track people perfectly, which you can't, who the hell thinks it's okay for data to get leaked as long as you know who it gets leaked to?
- throwaway894345 5y agoIt’s not a nice response, but IT needs to be able to answer questions about the extent of a given breach (what info was accessed by whom and when). This is a legal requirement in the case of health information. Ideally people could be courteous while fulfilling their legal obligations, but IT folks aren’t generally chosen for their public relations or customer service skills.
- vageli 5y agoIn those situations you get a third-party in for forensics, you don't typically ask the people who breached how large the breach is (why would you take them at their word anyway? aren't they incentivized to downplay, etc).
- frumper 5y agoIf he can monitor ip addresses to make sure this guy isn't browsing anymore, then he should be able to check those same logs to answer his own question. If you want people that have zero obligation to help you then you should probably be nice to them. The nefarious criminal isn't going to report things like this to you.
- throwaway894345 5y agoI already agreed that this doesn’t warrant unkindness.
- marcus0x62 5y agoYes, and they need to do that based on the forensic data available to them, even if the answer is “we don’t know, it could be everything.”. Asking the person who caused the breach to explain the extent of your data loss is not an acceptable, or reliable, practice.
- throwaway894345 5y agoI don’t expect that it is sufficient, but it probably gives the IT person something to tell their boss in the short term: “We’ll verify, but he says he only accessed X”.
- ajmurmann 5y agoAssessing the scope of the breach, sure. "Fixing" the breach by monitoring a single IP addresses access patterns not so much. The site needed to be taken down till a mitigation has been deployed.
- throwaway894345 5y agoAgreed.
- dymax78 5y agoVehemently agree. The response demonstrates, if nothing else, the lack of an appropriate Incident Response Plan. A competent legal team would not vet and approve such a response, instead redirecting it through the appropriate channels if they felt the need to respond directly.