3 ms·
I'm not really sure what to think about this yet. I suppose comcast has the consumer customer base so when news like this breaks shade naturally gets thrown th
by bsmartt 3y ago
I'm not really sure what to think about this yet. I suppose comcast has the consumer customer base so when news like this breaks shade naturally gets thrown their way. But it's hard to fault comcast for having netscaler infra (which i guess was acquired by citrix at some point? dont quote me on that). 9 days to patch isn't really what I call blatant negligence (which is what i'd like to think would make me likely to terminate my contract). It's not always easy to just yank node balancers from your perimiter, especially if you have as large and probably ugly permimeter as comcast does. I'm sure that most people on this site had very little faith to lose in Citrix/Netscaler prior to this incident, so it's not a surprise there's little focus on them here, but as far as the consequences in any form, I really doubt Citrix / Netscaler will face enough punishment. It's also unclear to me exactly what the consequences of this data leaking are. last four of my social? Well, my full social is already out there, thanks to equifax (if no one else).
There's also the fact that a large number of companies were and still are being popped with citrixbleed, ransomware has gotten in line for this ride, and i bet it will take 6+ months for 80% of vuln systems to be patched/purged. Again, 9 days?
Ars technica's Dan Goodin has two articles about this (ive shortened them a bit):
Comcast waits 9 days to patch critical vuln
The latest high severity citrix vuln isn't easy to fix
come on...