4 ms·
They detected the incident on the 29th of December. I kinda think that regardless of what day they disclosed, from that day to today, people would find various
by _zn02 4y ago
They detected the incident on the 29th of December. I kinda think that regardless of what day they disclosed, from that day to today, people would find various reasons to complain- "to soon to know what happened", "the day before New Years", "the day after New Years", and "too long after the event". In snark I will suggest that's a pessimist voice you're hearing- the cynic in me wonders if there's any time to disclose that won't receive a complaint.
- bostik 4y agoSlack probably has a lot of large - and very demanding - enterprise clients who absolutely require their non-trivial service suppliers to have infosec policies with a maximum of 72-hour notification window for security breaches. And I can guarantee that no company wants to have client-specific notification window policies in place. That way lies road to madness, missed commitments and nasty litigation. It's a good practice, in all honesty. The time window is for the initial notification, after that there will be subsequent notifications when actual investigations complete.