Hacker News new | ask | show | jobs
by m3047 1401 days ago
Do you practice know your customer (are you required to)? Is this shared hosting? Who runs the site? Who is responsible for security? What are your assets? Any other way(s) for them to be compromised? Where are your backups; did someone get ahold of those?

What about all of the garbage that people pull in from the webs (and into their customer's browsers)? Do you know why fonts.google.com is controversial? Is some ad network participating in a watering hole attack? Got a chatbot on your payment page?

Once you have a handle on that, you can start looking for answers. If that's too much to ask, then the time to start paring down your attack surface is before there are questions.

Use hosting that provides such guarantees. Use an MxP. Don't keep customer information you don't need. What you quote is facile.