6 ms·
Ouch """ Earlier today, a public relations firm working with Sisense reached out to learn if KrebsOnSecurity planned to publish any further updates on their br
by dudus 2y ago
Ouch
"""
Earlier today, a public relations firm working with Sisense reached out to learn if KrebsOnSecurity planned to publish any further updates on their breach (KrebsOnSecurity posted a screenshot of the CISO’s customer email to both LinkedIn and Mastodon on Wednesday evening). The PR rep said Sisense wanted to make sure they had an opportunity to comment before the story ran.
But when confronted with the details shared by my sources, Sisense apparently changed its mind.
“After consulting with Sisense, they have told me that they don’t wish to respond,” the PR rep said in an emailed reply.
"""
- deleted 2y ago[deleted]
- mulmen 2y agoThey wanted an opportunity to comment. That implies no obligation to comment.
- ethbr1 2y agoIt does say something that they were interested enough to want the opportunity, but specifically chose not to exercise it. Thought it was a nice addition to the piece.
- mulmen 2y agoWhat does it say? I think adding the comment that they “changed their mind” was unreasonable because they didn’t change their mind. They wanted an opportunity which they got but didn’t exercise. They didn’t say “don’t contact us for comment in the future.” Which would be “changing their mind”. Their comment was simply “no comment”. This seems completely reasonable to me.
- ethbr1 2y agoThat they weren't even prepared enough to say "We at Sisense take security very seriously. Highest priority. Industry standards. Etc. Etc."
- mulmen 2y agoThat seems like a leap. I’m not sure what value can be gained from such an assumption.
- ethbr1 2y agoIncompetence.
- mulmen 2y ago“No comment” doesn’t seem like an incompetent comment. Why do you assign more value to unsubstantive PR speak?
- ethbr1 2y agoBecause "no comment" is less of a plan than even mindless PR pablum, that a PR agency should have been able to churn out without thinking. Unless Sisense (a) had no prepared PR plan for this scenario and/or (b) has no idea what actually happened, so are still terrified to legally expose themselves by putting any words to paper. E.g. They still haven't put out a press release: https://www.sisense.com/newsroom/ https://www.sisense.com/newsroom/ Aside from, you know, their piece on how properly isolated multi-tenant is a secure architecture pattern: https://www.sisense.com/blog/benefits-of-next-generation-multi-tenancy-to-embedded-analytics/ https://www.sisense.com/blog/benefits-of-next-generation-mul...
- mulmen 2y agoWhat if their prepared plan was “no comment“? I think you’re making an unreasonable number of assumptions.
- ethbr1 2y agoDo you think "no comment" is a good plan, when you've just sent out an emergency email to all of your customers telling them to rotate any credentials they entrusted to you?