4 ms·
Why are we reading this on the SEC site and not the GoDaddy site? I did a quick search and can't find a disclosure on their site. If it's there, it's not easy t
by marcc 5y ago
Why are we reading this on the SEC site and not the GoDaddy site? I did a quick search and can't find a disclosure on their site. If it's there, it's not easy to find.
Security incidents are going to happen. This particular incident looks to be avoidable (static passwords!). What we should judge the company on is their response and transparency. GoDaddy disclosed, but a new customer on the site wouldn't find this. They also used phrases like "affects our Legacy WordPress Platform" probably to attempt to shift a little blame from the current team or minimize the fall out.
When you have a security incident, be transparent, own it, and deal with it. We can tell when you are trying to sweep it under the rug and hide, and that's bad. This is an opportunity for an org to show that they put customers first and shine.
- elliekelly 5y agoManagement doesn’t put customers first. They put themselves (management) first closely followed by investors. The SEC recently indicated they’d be focusing enforcement on cybersecurity incident disclosures. Particularly on timely disclosures (not waiting 6 months from discovery to disclosure, for example). That might be the only reason we’re even reading about this at all.
- hellbannedguy 5y agoGodaddy has always been a slimy registrar. Amyone who has registered with them knows this. Go with Goole for $13. You will never hear from them. You won't have to worry about drug fueled marking bs, or unethical behavior.
- bagels 5y agoGoogle?
- verdverm 5y agohttps://domains.google.com https://domains.google.com Also a long time happy customer.
- cycomanic 5y agoI realise that you are talking about behavior as a registrar, but it's somewhat ironic that you mention google and no unethical behavior in the same sentence.
- hackmiester 5y agoI absolutely hate Google, but if it was between them and GoDaddy, I think I'd pick Google. If I had any choice, though, it'd be Gandi or Namecheap.
- zinekeller 5y agoGoogle Domains has indeed been a very professional and no-BS operation. Shame though that their other businesses are... not in a good spotlight. Edit: Whoops, CRR operates certain gTLDs, Google LLC operates the buy-a-domain registrar.
- RHSeeger 5y agoAnd if you ever have a problem with them, you _still_ won't hear from them.
- blablabla123 5y agoThat's at least the 2nd funny thing happening with GoDaddy. I stopped using them years ago.
- skeeter2020 5y ago>> Why are we reading this on the SEC site and not the GoDaddy site? This is typically by design and public relations 101. If you don't link "bad" content to your domain it's easier to make it disappear in the future. It's why a company purchases "our-data-breach.net" to handle a public incident instead of just a sub domain or deeply linked page. No long-lived anti-SEO
- neom 5y agoThe URL contains "gddyblogpostnov222021" - and at the bottom the FLS mentioned blog post, so I guess the SEC didn't adhere to their press embargo on the blog post? ;)
- secondaryacct 5y agoSorry but they are contacting every impacted customers and changing their secrets. You work in a company too, what matters ? That the random raging virgins on HN bask in your failure, or that every impacted client knows something happened ?
- deleted 5y ago[deleted]