Yes, we're hoping to do a post-mortem soon on our engineering blog, so that others can learn from our experience.
Yes, we're hoping to do a post-mortem soon on our engineering blog, so that others can learn from our experience.
I originally intended to convert it to a disclosure generator, but I haven’t had the time.
I hope it can be of some help to you in dealing with this awful situation, and I’m terribly sorry this happened to you.
What you urgently want is a cultural change on behalf of industry. This guy is part of the change you want. Biting his fingers is not the optimal path to accomplishing your goals, even if it is viscerally satisfying.
I too want urgent cultural change on behalf of industry; I'll settle for regulation though.
This is already the case in the EU with the Data Protection Directive.
..and
"We have since improved our security procedures and systems in numerous ways"
Perhaps when you do the blog post you could elaborate on what simple things (that were implemented in a few days?) were done especially why they didn't exist in the first place? An example being "we didn't do x because we thought y but now know that isn't the case so we are taking z extra precautions".
Also did you have outside security auditors and could they have done a better job? And if not, why not?