4 ms·
Perhaps you have a different definition of investigation than I do. I see the investigation as the active bit where you are talking to people, looking through l
by SoftwareMaven 12y ago
Perhaps you have a different definition of investigation than I do. I see the investigation as the active bit where you are talking to people, looking through logs, trying to figure out what happened. At the end of that, you would have a report that said "this is what happened: this is the data that was lost and this is how it was done". That doesn't imply that every interview and every log file gets published.
Of course there is going to be some level of sanitization, but today we get no information beyond "we lost a bunch of data" (oh, look, they told us names, address, email, "and other information used to categorize customers", whatever that means).
If you decide it's not relevant to you, brilliant. Don't pay attention to it. It is relevant to me, because I don't have any other way to decide who I should trust with my information security. A company losing hundreds of credit cards a day to hundreds of different hacks is much less secure in my mind than a company that loses 70M names and addresses (as far as I know, the Chase hack did not expose credit cards; mine was not replaced). The former goes unreported; the latter gets splashed all over the news.