FTC takes action against GoDaddy for alleged lax data security
ftc.gov
ftc.gov
GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome.
If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this one occur)
As SRE, I've heard executives say this "There is no penalty for breaches, why care?"
Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected.
We get training on it every six months.
I have started to put together some resources to teach C suite, maybe new-to-the-field lawyers, other interested stakeholders - about website compliance issues..
looking to mimic other good training / learning materials, extra info to consider, maybe collab and send business I can't take on, etc.
There are some out-of-the-box solutions that can start you on your way to creating a security awareness training program, such as KnowBe4 and ProofPoint (there are others as well, but these are some of the big names). If you don't have in-house security staff, these types of offerings can be quite helpful.
For a more grounds-up approach, there are guidelines such as the NIST SP 800-50 "Building a Cybersecurity and Privacy Learning Program" guidance. (https://csrc.nist.gov/pubs/sp/800/50/r1/final)
If you have specific questions, I can try to answer them.
And, from my experience, many of the trainings that seem almost offensively easy to me (e.g. "How to read a URL") have been some of the ones that received the most positive feedback from non-technical departments.
The real key with security awareness training is ensuring the training is at the appropriate level of complexity for the trainee.
Appreciate you and @ziddoap offering insight!
Looking at starting deck for FTC issues, Hipaa issues, and Google's policies - all for websites and apps specifically very soon and let the videos / webinars / interactive / discussions grow from here.
Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"
It's also disproportionate. If my email is leaked in the context of receiving treatment for a stigmatized disease, that's a lot worse than an MMORPG leaking my real name.
Maybe some penalty is necessary but $10k or above per user is disproportionate for the vast majority of people. A $50/person penalty with gradations for sensitivity of the information is going to work better in practice. If leaking an SSN is more expensive than an email or site-specific ID, corporations might stop using SSNs to identify people to reduce their exposure
If the outcome of ignoring data security is to not make any money then companies will actually do something about it.
Penalities should push the company to the point of failing.
You phrasing it like this is not a substitute for explaining why it wouldn't be those things.
Also, the most obvious thing is: if you're a healthcare provider, you would probably hire some hackers to go after your competition, and let heavy-handed fines take them down. Much easier than providing better value.
I got a letter telling me they gave away my information with a link to an “identity monitoring” site that looks like the CEOs nephew built in a weekend and just errors out when I sign up.
Even better, the consequences are stronger in the event that the company obviously wasn't giving a fuck about security.
I wish we had HIPAA for all PII.
Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.
There are so many alternatives to what GoDaddy provides, it is quite commoditized.
But also... true, their customers don't seem to care anyway? Or it's "cost of switch", even just mentally? If you were starting fresh it really wouldn't be any harder at all to go with any of numerous alternatives, but if you already have godaddy...
EDR (especially Windows EDR) is heavily commodified.
Did you move to a new bank after yours had a security breach?
There are so many breaches these days, companies don’t even have liability — any damages can be blamed on another breach.
Worse. It's a market where most of the customers are unsophisticated but price sensitive, so they tend to prefer the provider with the lowest apparent price, and then the big providers compete on the basis of who can present the lowest apparent price through the use of dark patters, misleading claims, bait and switch tactics and hidden fees.
Example: GoDaddy provides a "free" site builder but if you use it the resulting site can't easily be extricated from their service and now you're locked in if you don't want to recreate your site. Meanwhile the price you were quoted for various services was an onboarding price and now that you've sunk a lot of time creating and improving the site you can't move, the price is going up.
This is, incidentally, a major reason WordPress is so popular despite being fairly miserable. It makes it easy for unsophisticated users to get started and your site isn't tied to a particular host.
A couple of days of production stopped can cost a lot of money.
it takes time there are plenty of lawsuits flying around that incident .
Even if they win all the suits without settling or loosing, customers will negotiate far stiffer penalties and controls on next renewal or get steep discounts or just straight up switch vendors .
Sooner or later their ability to be competitive will get affected and they will likely become a target for acquisition and rebranding.
Organizations of that magnitude do not collapse overnight like startups
switching from godaddy to another registrar is not super hard, but there are hurdles and sometimes problems occur that even people with experience run into.
I think (some?) people also hope a place that suffers a breach learns from it and makes it near impossible for similar to happen again.
The only people who's reputation gets ruined are the D-Level Directors and Managers who run this stuff and regularly run into budget or resource shortfalls that prevent them from doing all that they are capable of doing.
but do I blame the average person for not caring? The kind of person who would use GoDaddy for hosting? I find it really hard to blame them.
Yes, the CRWD ticker took a hard hit, dropping about 50% over the course of 2 weeks last July. But... it recently topped its previous high, only 7 months later (which is like 1/2 or 1/3 of an enterprise sales cycle!).
Every regulatory agency in America has been stripped to the bones by decades of budget cuts and never ending accusations of "stifling innovation" and we're shocked now that companies get away with both metaphorical and actual murder.
If it wasn't for those old Super Bowl ads, GoDaddy wouldn't exist today.
Sex sells.
GoDaddy attracts the unwashed masses who don’t care about security, and who remain unphased after learning about breaches. Meanwhile, the tech-savvy crowd who would care about breaches already know to avoid GoDaddy and view the inevitable breaches as the plebs reaping what they’ve sown.
Ergo, no one getting breached by GoDaddy cares, and nobody informed watching it happen feels a need to intervene.
GoDaddy CEO's graphic elephant hunt video sends his clients flocking to competitors, and helps raise $20,000 for elephant charity:
https://www.dailymail.co.uk/news/article-1374679/GoDaddy-CEO...
GoDaddy CEO Kills Elephant:
The security breach we're discussing didn't happen 14 years ago, as you well know. They have a long and infamous track record and toxic corporate culture and unethical business practices and willfully misleading negligence of security that show no signs of improving.
So charming that you're on such a familiar first name basis with a piece of shit like Bob Parsons. Are you friends? Are you actually carrying the water for GoDaddy, or think it's ok to murder elephants and run incredibly sexist commercials while never giving a shit about security or customers? Yuck.
I have had to tell multiple cybersecurity vendors that brag about working with huge companies and governments that we cannot work with them because of how poor their own cybersecurity practices are (i.e. not using secure compute/hardware crypto when dealing with our private keys).
These are companies that should know better, I have had to stop ADP professional services more than once from disabling certificate validation on critical pipelines pertaining to confidential employee and customer information. I do not want to imagine what happens at 99% of companies with cybersecurity teams that don't even know what certificate validation is.
It's a tough business hosting arbitrary UGC, and doing it well costs a lot of time effort and money (ask me how I know). But I fully agree: treating this as just another line-item cost is absurd.
I worked for a medium sized company. They had a very large commercial e-commerce site for their customers. They used Wordpress sites that were hosted on GoDaddy. I worked there for two years. They never updated any of their passwords for GoDaddy or their Wordpress sites.
Its been almost ten years since I've worked there and I occasionally log on just to see if they've updated anything. Nope. Last time I checked was early 2024. Still nothing was updated.
I mean, someone gets access to their GoDaddy account and within minutes will have full control of a major bit of their business. Talk about playing with fire.
... but.. why?
Why let them live rent-free in your mind? Why admit to that in even a pseudonymous space?
... Honestly it reminds me of how some Internet VOIP providers won't tell the name of the business who actually bought the number (Which, of course, complicates the ability to collect on TCPA when it's a number used for spam.)
I ran a website hosted on GoDaddy for a local business when the server cluster was hacked. GoDaddy admitted it was their fault, but the business ended up having to pay me to fix the site. GoDaddy also managed to convince the business to pay for an additional monthly "security" plan, which included page caching. They set everything up over the phone without talking to me at all.
The next day I notice some odd behavior with the admin pages, then realize they're being cached, not only that but they're now publicly accessible. GoDaddy's improved security plan ended up being responsible for a data leak. They really screwed up twice but there was zero penalty, the only consequence was they made more money. The business chose to stay with GoDaddy, despite my recommendations. They saw the ads on TV and were convinced GoDaddy is the pinnacle of web hosting.
Also, check this out: https://www.butterflyave.com/
Those assholes have parked my old business name, and want to sell it back to me for $1,499.
I have zero trust in GoDaddy. I remember when I was kid using their service because my grandparents had bought a website and hosting services through them and they wanted me to create the site. Their interface was so confusing and I felt like I suddenly had no understanding of how computers work.
Fast forward to today, and yes, past me was not very knowledgeable, but not to the degree their site made me feel. They use custom terminology for industry standard things, group things together in weird locations, and have so many dark patterns.
My point: sleazy tactics like domain front-running would honestly be on brand. I tell people not to use GoDaddy and definitely not for domain searching.
It show a cavalier attitude toward the greater security of the internet.
If every stolen or potentially stolen credential was billed to the breached provider at even $100/account*, SSO would become free so fast your head would spin.
Every credential in the provider's DB would be correctly seen as a liability.
* Arguably the number should be higher and contribute to a infosec response, detection, and preventative measures warchest. Though, ultimately, this would probably just enrich cybersecurity insurance firms.
Another example is Microsoft charging extra for enhanced logging. This came to light during the SolarWinds debacle.
Subtle but important difference.
Also the remedies include having a complete security program within 90 days IIRC, on what world would anyone think that’s remotely possible?
They wouldn’t even have an RFP drafted in 90 days.
GoDaddy is big, safe and terrible. Network Solutions is big, safe and even worse.
The worst part is that when replacing an A record with a CNAME, it lets you delete the A record but then blocks you from adding the CNAME, because "a record with that name already exists" (referring to the one that was just deleted). This is where the 20+ minute wait changes from "inconvenient" to "downtime". It's been like this for at least 15 years.
Crazy.
Long story short I got locked out of my account. It truly seemed like the support didn't want to help me get back in. This went for what felt like forever but was probably just a few weeks. I never got a resolution and was never able to log back in to my account.
I eventually did a chargeback because I couldn't use a service that I was paying for. They were all of a sudden proactive about reaching out - with an accusatory email nonetheless. In their view, the chargeback was fraudulent.
FWIW we've used Gandi for years and very happy with it.
After that I've used spaceship.com, NameCheap's rebrand, without complaint and most recently porkbun.com due to support in dnscontrol.
Who else is there that the average person would know about?
And their UI for choosing a domain name is excellent.
Maybe GoDaddy just sells themselves better? I see Squarespace as kind of an amorphous boring blob of internet business services.
For a long time, I worked in an office across from their (now former) headquarters in the Scottsdale Air Park. The number of clients we had come in amazed that we must work so closely with them and expecting great things made the location of the office so invaluable that when they moved to Tempe and Chandler, we had to seriously discuss internally if we needed to follow them.
Anyway. Nice to see the FTC getting a few wins in before they are defanged by the new administration.
Although it's a real ICANN rule, the registrar is allowed to override it if they want. Of course very few registrars offer that kind of customer service, so that escape hatch might as well not exist...
I still have a .com domain that I've registered from when I was a child and I've just never bothered to update the information on it, the regulations on these are as lax as godaddys security.
If you're a site with millions of views a day this might be different.
People will put up with all kinds of awfulness if they don't know better.
https://www.golfdigest.com/story/an-unofficial-ranking-of-th...
The Woman(!) Behind GoDaddy's Tasteless, Effective Super Bowl Ads:
https://www.forbes.com/sites/jeffbercovici/2013/02/06/the-wo...
Who Let These Commercials Be On TV?
https://www.youtube.com/watch?v=_rRopnyZaR0
GoDaddy's most infamous ads:
https://www.youtube.com/watch?v=u7yFCqOAb9Y
10 SEXIEST GoDaddy Super Bowl Commercials - Sexy Super Bowl Ads:
If you'd like to see what the new admin's FTC is spending your tax dollars on instead of this, take a look here: https://www.ftc.gov/news-events/news/press-releases
(Sounds like hyperbole, as it’s not like non political people just all got replaced.)
This is not hyperbole.
Give it 6-12 months and we'll see how the courts react to challenges and if Congress suddenly grows a spine. And if a mid-term swing back to normalcy seems likely.
Trump already "deported" legal american citizens his first term. Trump supporters openly insist on "deporting" a legal american citizen who dared to tell Trump that he's a meany.
The Constitution is just a piece of paper. None of the people in the Trump admin care about it or respect it. It will not save us. The guardrails are all gone.
And you're right, ICE could well be on its way to turning into the Stasi.
When there is an opening and there are already 3 from the President's party traditionally the President asks the Senate leader of the other party who should be nominated and the Senators of the President's party do not vote against that nominee.
As someone with 20+ years experience in IT/DevOps/Cloud/whatever, I disagree.
They would simply need to actually use the security that is already there. Data leaks that happen due to lack of "very good security" are extremely rare. In almost every case, someone was doing something very stupid that everyone already agrees is a very obvious thing to not do.
.
> In fact companies would go out of their way to not store any of your data.
The companies that already use existing IT systems, as they are already designed to be used, have no problem protecting customer data and not leaking it. The companies that can not properly hire our outsource competent IT people shouldn't be storing data in the first place. Commerce is subject to regulation, due to human nature, and different regulation is needed today.
.
> and insurance to cover themselves in case they do lose your data
I would prefer that this kind of insurance not exist.