6 ms·
In a very large company like Disney there are often legal data retention requirements from ongoing litigation, which means Corporate Slack might be more complic
by KerrAvon 2y ago
In a very large company like Disney there are often legal data retention requirements from ongoing litigation, which means Corporate Slack might be more complicated than the AT&T customer data breach.
- deleted 2y ago[deleted]
- Zondartul 2y agoWith how big and aggressive Disney is I'd expect it to be under ongoing litigation 24/7/365.
- 05 2y agoProper logging for retention would surely involve a point where you encrypt the data with a temporary key and then encrypt that key with the public key and only your top brass would have access to the HSM that could decrypt that blob..
- nyrikki 2y agoRetention doesn't require it to be online. A tape sitting in Iron mountain would have a smaller attack surface and be compliant. Potentially this breach will allow litigation that was financially infeesable for some people. As a former WDIG employee I am not even suggesting anything concrete or that I have any knowledge of unlawful activity. But as someone who also worked in the electronic evidence discovery field, the cost of blind discovery has a chilling effect on lawsuits. Now that targeted discovery is possible, it will be within the budgets of more potential cases. The forever retention was a marketing differentiator for Slack, so this type of events were a risk you have to accept. But all about convenience and not compliance.
- BoredPositron 2y agoWith how many people in this thread don't see the problem with keeping all data always hot... we are fucked.
- JSteph22 2y ago>Retention doesn't require it to be online. Conversely, offline doesn't mean unhackable/unleakable.
- nyrikki 2y agoAs nothing is unhackable, that is a false dicotomy. Why use passwords at all under that line of thinking. That is why we talk about reducing attack surfaces.