7M Adobe Creative Cloud Accounts Exposed to the Public
comparitech.com
comparitech.com
Germany, the government, does this. They routinely scan systems in Germany and alert the owners to security issues.
I wonder if this is something all governments should do. I'm not convinced yet, but heavily leaning toward that it is something governments should do.
Exposed servers are a national security risk. They are a risk to public safety. Governments are there to protect their citizens.
The functions of the BSI are explained in English here [1] based on the following law [2]. I guess initiatives such as informing about the NTP problem fall into what is listed under §3.2.
[1] https://www.bsi.bund.de/EN/TheBSI/Functions/functions_node.h...
[2] https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/BSI/bsig...
Example: hetzner.
Arguably, by not telling companies about holes in their systems, they are doing the exact opposite of what they were founded to do: secure the US.
Just like we notify people when there's a fire hazard, we don't just stand idle when many people are at risk of something.
And then they would all do it because everyone would prefer that they rather than a foreign government are the ones holding 0-days during the remediation period.
How long before Adobe reaches the Oracle stage of dickhead'ness where phasing out all their products can be found in large companies (non-public) strategy plans.
But you do make a point. Often there is no obvious alternative. And changing tools has a cost.
Mostly because they want to pay for software and then not have it stop working on them for silly reasons, but also due to a general "bullshit fatigue" with Adobe. It isn't a company that cares a great deal about its users.
I did something similar a few years ago. After Oracle ended up buying Sun, I really wanted to stop using Java since I didn't feel Oracle was a company that I would want to do business with.
However, it took me several years to transition away from Java. I really liked Java. Finding a new programming language that is suitable for the kind of work you do, has enough of a community etc. isn't just a matter of deciding to move. You need somewhere to move to. Eventually Go evolved to where it fit my needs really well, so I managed to make the transition. 2-3 years later and I haven't touched Java since. (Which was somewhat unexpected. I didn't expect changing languages would be that fast, but it coincided well with new projects etc).
As for switching editors, VSCode managed to attract 2.6M monthly users in roughly 2 years. If you believe estimates of how many developers that are in the world, and you squint a bit when comparing numbers, that's roughly in the neighborhood of 10% of the global developer population.
My intuition says you are right. The data seems seems to suggest it wants to disagree with both of us :-)
Oct 31, 2014: 70.12
Oct 27, 2019: 270.98
(Source: https://ycharts.com/companies/ADBE)
Creative Cloud was launched in 2012. Looking at the historical chart of the stock price, it seems to have done wonders for the company.
1) check back on Monday morning
2) we don't know what their stock price would have been otherwise
3) even if it is good for their stock it might still kill the company, though - regrettably - the public is way too accepting of these sort of things.
Interactions between people can to a large extent be governed properly but utilitarianism but as soon as you bring in stockprice as the arbiter then you're very far from safe ground. After all; in times of war the stock price of weapons manufacturers will go up but that does not mean that the net utility gain is positive.
Microsoft and Apple are already calling for this, it's a matter of time.
I don’t believe that to be true. Sure, maybe if you bought boxed software from a physical store the opportunity for data breach is limited to your name and credit card information. But if you bought a license online to download you would still have the same risk of information breach as we see here. During checkout to buy the license I’m sure they wouldn’t collect some combination of email address, license purchase date, address, CC number, etc.
Email addresses Account creation date Which Adobe products they use Subscription status Whether the user is an Adobe employee Member IDs Country Time since last login Payment status The data did not include payment information or passwords."
"
* Email addresses
* Account creation date
* Which Adobe products they use
* Subscription status
* Whether the user is an Adobe employee
* Member IDs
* Country
* Time since last login
* Payment status
The data did not include payment information or passwords"
One document I read put the lower floor at 5 records for a 'major breach' so I would very much caution against trying to wipe this sort of thing under the carpet. That's the best way to find out how serious the EU is about those fines. That and repeats while ignoring previous DPA instructions.
I’ve been noticing increased scans for their default ports on servers I maintain.
It’s not very surprising given how insecure the defaults are for the typical ELK stack, and how tedious it is to actually setup sane authz.