4 ms·
I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were t
by dwoosley 3mo ago
I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had been breached in the past. Until the execs and board see the dollar impact themself and not just read about it, the security program never gets the funds it needs.
I’m not saying I recommend LastPass for that reason, but I wouldn’t write them off for that reason.
- gonzalohm 3mo agoBut LastPass has been breached multiple times by now. I don't think they really care
- dwoosley 3mo agoThere are lots of types of a “breach”. The first and second (the major ones) were likely related so more like one continuous incident. This one was a vendor breach that had access to their data so not a reflection of their security program as much as the first. I’m not saying you’re wrong, I’m saying you can’t tell from this incident.
- sys_64738 3mo agoWhat happened to the old days of only getting one chance to f-up? Once chance and they should be gone permanently.
- felmos 3mo agoIf the execs and board of a password manager company need to experience a breach to take security seriously, I don't really know what to say.
- dwoosley 3mo agoWeirdly being a security company actually can have the opposite affect. A small portion of potential customers or investors assume the company is more secure because they are a security company after all (and should be); therefore, the customer's security review are less stringent so exec can get away with smaller internal security budgets. Of course good security companys with good leadership doesn't do that... but those aren't the big companies.