4 ms·
> Despite being one of the compromised companies, the TJX spokesperson added: "We do not believe there was any unauthorized access to any customer or associate
by darkclouds 3y ago
> Despite being one of the compromised companies, the TJX spokesperson added: "We do not believe there was any unauthorized access to any customer or associate personal information on TJX's systems or any material impact to TJX."
I love how legislators have upped the ante for (big) businesses to survive, to the point some will appear to perjure themselves in public as the lessor evil.
https://gdpr-info.eu/issues/fines-penalties/#:~:text=For%20especially%20severe%20violations%2C%20listed,fiscal%20year%2C%20whichever%20is%20higher https://gdpr-info.eu/issues/fines-penalties/#:~:text=For%20e....
However, are legislators trying to kill the golden goose, has the money printing exercise called quantitive easing given them an unfounded level of hubris for their central bank purchased national debt?
- ackondro 3y agoI'm not saying this is how it happened, but this is why they may be able to say that. When working with similarly sized companies, I am required to encrypt the files (PGP zip) and transmit over a secure encrypted channel (SFTP). Normally, those companies will use a feature of Moveit to automatically do the PGP encryption/decryption. However, TJX could have written their security policy such that their Moveit server was not allowed to use that feature, so they used a different piece of software to do the encrypt/decrypt outside of Moveit. Thus, hacking the TJX server would only get a bunch of unencrypted reports and encrypted files with personal info in them. Again, I'm not saying this was what actually happened.