3 ms·
He said he believes the credentials were stolen in breaches that have yet to be publicly reported. This really bugs me. It seems like many companies are either
by jfc 13y ago
He said he believes the credentials were stolen in breaches that have yet to be publicly reported.
This really bugs me. It seems like many companies are either completely unaware that a breach has occurred, or know about it and are taking their time notifying customers (for PR or other purposes). Either way, customers are not getting this information in a timely manner, and that needs to change.
- mathattack 13y agoAlmost by definition, if you're dumb enough to leave a hole in your security, you're not dumb enough to realize when it's been broken. There are exceptions, but unless you've been harmed by the action, it's hard to find someone if you don't even know where to look.
- niemeyer 13y ago> if you're dumb enough to leave a hole in your security This is grossly underestimating how hard it is to have a bullet-proof system. Some of the best security people in this planet use disconnected systems when they want to be sure it is safe.
- mathattack 13y agoFair enough. Is it more accurate to say, "If you don't know where the hole in your security is, it's hard to know if it's been compromised."?
- shiftpgdn 13y agoI worked for a pretty major webhosting firm in the past that had multiple breaches that resulted in all customer identification data being stolen. It was never announced to the public in any way and even kept from most employees. I imagine many unscrupulous business owners do not report breaches for fear of bad PR.