8 ms·
Thanks for the good wishes. Yes, we're hoping to do a post-mortem soon on our engineering blog, so that others can learn from our experience.
by mecredis 13y ago
Thanks for the good wishes.
Yes, we're hoping to do a post-mortem soon on our engineering blog, so that others can learn from our experience.
- tptacek 13y agoThat's generous of you, and I appreciate it.
- victor9000 13y agoThe sentiment of your comment is that transparency is somehow generous; and I could not disagree more. As user whose information has been potentially compromised, i expect nothing less.
- patio11 13y agoYou can expect whatever you want, but the norm in industry is for that sort of information to end up in a silo inside the company, and external exposure to it is permitted only under NDA or equivalent guarantees (e.g. sharing with law enforcement). What you urgently want is a cultural change on behalf of industry. This guy is part of the change you want. Biting his fingers is not the optimal path to accomplishing your goals, even if it is viscerally satisfying.
- toomuchtodo 13y agoPerhaps regulation needs to move from mandatory disclosure when credit card/payment data is leaked/lost to mandatory disclosure when credential data is lost as well. I too want urgent cultural change on behalf of industry; I'll settle for regulation though.
- tptacek 13y agoBe careful what you wish for. Very few practitioners in this industry really understand what kind of regulatory honeymoon they're enjoying right now. Given the impact of the work we do to society, it is kind of a miracle we don't all have to be certified.
- toomuchtodo 13y agoShould we not make more effort to self-govern then? And not think it a gift when someone does a breach post-mortem?
- rmc 13y agoPerhaps regulation needs to move from mandatory disclosure when credit card/payment data is leaked/lost to mandatory disclosure when credential data is lost as well. This is already the case in the EU with the Data Protection Directive.
- larrys 13y ago"Upon learning this, we immediately closed the security breach and began strengthening security measures throughout the Kickstarter system." ..and "We have since improved our security procedures and systems in numerous ways" Perhaps when you do the blog post you could elaborate on what simple things (that were implemented in a few days?) were done especially why they didn't exist in the first place? An example being "we didn't do x because we thought y but now know that isn't the case so we are taking z extra precautions". Also did you have outside security auditors and could they have done a better job? And if not, why not?
- pessimism 13y agoOver the many hacks (breaches, as companies prefer to call them) we’ve come to see, as a user who at times felt nervous about how I was affected, I have tried to write a simple guide for how companies can disclose a hack in a way that will assuage my concerns in the best way possible: https://gist.github.com/ndarville/5072091 https://gist.github.com/ndarville/5072091. I originally intended to convert it to a disclosure generator, but I haven’t had the time. I hope it can be of some help to you in dealing with this awful situation, and I’m terribly sorry this happened to you.
- joshka 13y agoHave you considered submitting the usernames (email addresses) to Have I Been Pwned? https://haveibeenpwned.com/ https://haveibeenpwned.com/