5 ms·
Its good that they own up to it but I'm getting a bit tired of hearing "we take security very seriously." I feel like this phrase has become the mating call of
by click170 11y ago
Its good that they own up to it but I'm getting a bit tired of hearing "we take security very seriously."
I feel like this phrase has become the mating call of organizations who aren't serious about security until they get hacked.
- benihana 11y agoGreat response from jedberg about the business costs of security and the fact that a company can take it seriously and still have a breach: https://news.ycombinator.com/item?id=9834461 https://news.ycombinator.com/item?id=9834461
- Encosia 11y agoObligatory: http://www.troyhunt.com/2015/07/we-take-security-seriously-otherwise.html http://www.troyhunt.com/2015/07/we-take-security-seriously-o...
- shredprez 11y agoWas just about to comment. Ever since I read the article, it's the first thing I notice (whether or not that's fair).
- pekk 11y agoDoes it follow that if an organization discloses a security issue, it wasn't serious about security?
- fixermark 11y agoI'd call this an exception. An organization that is willing to take one on the chin, so to speak, by declaring a breach of their policies even in the absence of evidence of abuse of the policy violation is actively demonstrating their commitment to security before they've been hacked.