Hacker News new | ask | show | jobs
by josefritz 926 days ago
True. However, their abdication of responsibility is indicative of a lack of a security culture. It's hard to say that they were more or less negligent than Equifax, but both data sets should have been Highly secure.

It's also interesting that outside of the US their lack of security would open them to criminal liabilities under GDPR.

1 comments

Equifax was more negligent. No doubt. EQ left default credentials intact on a public facing database.

23 was cred stuffed, which is still not good, but not the same level of negligence.

US laws are a sad tragedy of the rich fucking the not rich harder and harder and harder every decade.