6 ms·
I think the key here is that SolarWinds' C-staff deliberately downplayed the severity of the attack, and were very late in informing customers and regulatory ag
by suid 3y ago
I think the key here is that SolarWinds' C-staff deliberately downplayed the severity of the attack, and were very late in informing customers and regulatory agencies of the severity of the attack.
I.e. they are being prosecuted not because they were "incompetent and got hacked", but that they then "tried to cover it up", which is where the SEC comes in (illegal stock manipulation via false or incomplete release of public information).
- b112 3y agoI.e. they are being prosecuted not because they were "incompetent and got hacked", but that they then "tried to cover it up" Capone was taken down for tax evasion. Any tool we have, is a good one. And the more shareholders and board members feel lax security could lead to a bad path (eg hiding the result), the better for all. I can hardly wait for the first civil lawsuits, for any such incident, by shareholders over negligence and loss of value. I can hardly wait until everyone had to provide a license validation for all code they use, so we can finally put node crap to rest.
- philipwhiuk 3y ago> I can hardly wait until everyone had to provide a license validation for all code they use, so we can finally put node crap to rest. I don't see a reason Node dies faster than say, Java, or Rust or ...
- rkagerer 3y agodeliberately downplayed the severity of the attack You mean like UPS just did? https://news.ycombinator.com/item?id=36439033 https://news.ycombinator.com/item?id=36439033
- georgeplusplus 3y ago[dead]