|
|
|
|
|
by klodolph
2806 days ago
|
|
> But the users whose data was emitted should have been immediately notified. If we’re still talking about the same bug… I thought that there was no evidence that anybody’s data was exfiltrated through this vulnerability? Granted, absence of evidence is not evidence of absence, but who, exactly, are you saying should be notified? I would say yes, if some person’s PII data was improperly disclosed, yes, disclose the breach to that person. But if there is not any evidence that some particular person’s data was exposed here, do you go around telling people that their data “could have” been accessed, “if”? Physical security analogy—let’s say I found out that the window was unlocked. It’s been unlocked for three years, and I pull security tapes. Nobody is on tape coming in through the window, but the old tapes have been erased. I don’t have any evidence that anybody came in through the window, and yet I can’t disprove it either. |
|