6 ms·
Alternately, yet another right wing "alternative" site had poor security practices and got exploited. They had S3 buckets full of customer data sitting open for
by defaultname 5y ago
Alternately, yet another right wing "alternative" site had poor security practices and got exploited. They had S3 buckets full of customer data sitting open for some time, and they stayed accessible days after it was widely known.
- rvz 5y agoExactly. Just like GoDaddy and Twitch had poor security with everything that they stored on their servers from PII and source code getting breached and leaked by hackers right? [0] [1] I'm sure everyone was happy with that hackivism and those guys should have gotten their security right the first time. /s Can't wait for someone else to say, 'Security is so hard' but also cheer on hackers that breach sites they don't like. [0] https://news.ycombinator.com/item?id=28770590 https://news.ycombinator.com/item?id=28770590 [1] https://news.ycombinator.com/item?id=29306554 https://news.ycombinator.com/item?id=29306554
- defaultname 5y agoI don't think whataboutism is productive. Nor did I "cheer on" anything: It sucks when people are exploited by incompetent actors. We've repeatedly watched as "the mainstream restricts us so we'll do our own thing" sites are built with absolutely rudimentary security faults. They're rushed, have a very eager and non-discretionary userbase that is chomping at the bit. They usually have compromised motivations. And then they fall. It has become sadly predictable.
- rvz 5y ago> I don't think whataboutism is productive. Except that this isn't 'whataboutism' since I already agreed with what you said, that GiveSendGo definitely had poor security whilst also not supporting or justifying with hacktivists, criminals or script-kiddies attacking anyone's site. > Nor did I "cheer on" anything: Never directly accused you for cheering: I'm only predicting the obvious. If one is supporting hackers breaching other peoples websites they don't like, whilst defending another with that phrase which applies to everyone as an excuse for it, then you would fall under that category. > And then they fall. It has become sadly predictable. Yes, it's very predictable. Unfortunately it can happen to anyone. Whether if you are big like GoDaddy or small like GiveSendGo. These hackers are not on anyone's side.
- DoctorOW 5y agoNot sure about the details of the Twitch hack, but yeah the GoDaddy setup was pretty insecure. > Can't wait for someone else to say, 'Security is so hard' but also cheer on hackers that breach sites they don't like. The top comment of the GoDaddy post you linked literally says "This could have been an easily avoidable data breach."
- Arrath 5y agoTime and again these sites have demonstrated their disdain for security, and it bites them yet again. Anyone making the jump to conspiracy or state sponsored hacking is making quite a logical leap, imo.
- keneda7 5y agoSo just so I am no misunderstanding you here. You are implying if your site or company has poor security practices its okay for hackers to steal data?