5 ms·
I'm in favor of mandating disclosure. I wish they hadn't limited it to the vague 'has material impact' definition. Under that rule if a company is being DDOSe
by CSMastermind 3y ago
I'm in favor of mandating disclosure. I wish they hadn't limited it to the vague 'has material impact' definition.
Under that rule if a company is being DDOSed constantly but their network is successfully mitigated against it presumably they wouldn't need to disclose it.
But it would be in the general good of the public to be able to track these events, what their source is, etc.
At least this is a step in the right direction.
- clipsy 3y agoOn some level I'm inclined to agree, but there is a point to be made here that sufficiently large targets are attacked virtually 24/7 and reporting all of those may result in burying legitimate threats in the noise.
- seeknotfind 3y agoEven a silly blog I linked on HN a couple of times has gotten attacked 24/7 for a couple years. I still get requests with log4j injection attacks. Pretty sure any IPv4 address and any registered domain will get attacked regularly, especially if it's hosting something - anything. Heck, I pinged every IPv4 addresses in 2012.
- atkailash 3y ago[dead]
- kjs3 3y agoWhy would I need to disclose an attack that did nothing? I work at a financial, and someone, somewhere, is trying to DDoS us all the time. Should we be publishing "yup, same as yesterday, people are trying to put us off line" every single day? And I have worked in several other DDoS attracting industries (European sports betting? OMFG so much DDoS). What is the "general good of the public to be able to track" when it is literally happening all the time? Next you'll want us to provide reporting on port scanning.
- nubinetwork 3y ago> Next you'll want us to provide reporting on port scanning. Yeah I'll get right on that. You can read the database yourself. ;-)
- jdjdjdhhd 3y agoNot sure why you would need to report DDoSs anyways...
- halJordan 3y agoMaterial impact is the same guidance for non-cyber incidents. So it seems well established. The alternative would be a govt list of incidents and you would be complaining that we need a less brittle way of disclosure because the list is always 5 yrs behind. It isnt the SECs job to track that data. Its the SECs job to ensure companies are not lying to the point they're defrauding their owners. Take the complaint to the correct agency and let this one do its job.