[HN Gopher] FTC takes action against GoDaddy for alleged lax dat...
___________________________________________________________________
FTC takes action against GoDaddy for alleged lax data security
Author : luu
Score : 205 points
Date : 2025-01-28 07:02 UTC (15 hours ago)
(HTM) web link (www.ftc.gov)
(TXT) w3m dump (www.ftc.gov)
| josefritzishere wrote:
| I never thought I'd be a fan of a government agency. But here we
| are.
| coldpie wrote:
| Press release is dated Jan 15. The folks who made this happen
| are gone now.
|
| If you'd like to see what the new admin's FTC is spending your
| tax dollars on instead of this, take a look here:
| https://www.ftc.gov/news-events/news/press-releases
| jjtheblunt wrote:
| Why do you think they're gone now?
|
| (Sounds like hyperbole, as it's not like non political people
| just all got replaced.)
| grajaganDev wrote:
| Federal employees are being asked who they voted for.
|
| This is not hyperbole.
| zelphirkalt wrote:
| Is the US turning into "fourth Reich"?
| alistairSH wrote:
| My hopes aren't high at this point. Trump and the GOP are
| hellbent on implementing all of the P2025 agenda - many
| of the flurry of Eos this week were either literally
| cribbed from the P2025 document or strongly appear to AI-
| generated adaptations of the same.
|
| Give it 6-12 months and we'll see how the courts react to
| challenges and if Congress suddenly grows a spine. And if
| a mid-term swing back to normalcy seems likely.
| insane_dreamer wrote:
| Luckily we have enough remaining guardrails that it's
| unlikely to happen within the next 4 years. But we're
| getting closer, that's for sure. And the Supreme Court's
| disastrous decision on presidential immunity is allowing
| Trump to play Generalissimo.
| mrguyorama wrote:
| What guardrails are you talking about? Even ignoring the
| presidential immunity ruling that explicitly makes him
| Fuhrer, if Trump has ICE arrest all brown people
| tomorrow, what exactly is going to stop him? The courts?
| A judge can say whatever the hell they want from their
| bench, it won't stop an ICE agent from physically forcing
| you onto a C130 and taking you wherever.
|
| Trump already "deported" legal american citizens his
| first term. Trump supporters openly insist on "deporting"
| a legal american citizen who dared to tell Trump that
| he's a meany.
|
| The Constitution is just a piece of paper. None of the
| people in the Trump admin care about it or respect it. It
| will not save us. The guardrails are all gone.
| insane_dreamer wrote:
| I guess I've still been somewhat hopeful that the
| Legislative and Judicial branches will do their job and
| curb the worst of Trump's excesses or power grabs. But
| you're right that it's not looking good so far with the
| GOP Senate seeming to allow anything Trump wants so far.
| Hesgeth's confirmation was a really bad sign.
|
| And you're right, ICE could well be on its way to turning
| into the Stasi.
| coldpie wrote:
| Change "gone" to "out of power," if you like. The FTC Chair
| controls the agency's agenda, and the Chair switched
| parties last week.
| gs17 wrote:
| The new chair was nominated for the FTC (as a
| commissioner, not chair) by Biden.
| coldpie wrote:
| Yes, and?
| tjpnz wrote:
| >NOTICE: The FTC website is currently unavailable. Thank you
| for your patience while we work to restore service.
| gs17 wrote:
| It's back up, the only real announcements listed from the
| new administration are Ferguson as chair and anti-DEI
| changes (including a 2-1-2 vote to allow it where
| "Commissioners Rebecca K. Slaughter and Lina M. Khan did
| not participate.")
| DemetriousJones wrote:
| Latest press release: "FTC Grants Chairman Ferguson
| Authority to Comply with President Trump's Orders to End
| DEI"
| jmuguy wrote:
| I guess its just the power of advertising but its amazing to me
| that GoDaddy continues to be a popular solution for hosting,
| domain registration, etc given their absolute toilet of a
| reputation.
| lenerdenator wrote:
| They got their product out.
|
| Who else is there that the average person would know about?
| grajaganDev wrote:
| Yup they dominate mindshare.
|
| And their UI for choosing a domain name is excellent.
| bogwog wrote:
| Squarespace advertises a lot too, probably more than GoDaddy
| nowadays, and they are also a domain registrar.
|
| Maybe GoDaddy just sells themselves better? I see Squarespace
| as kind of an amorphous boring blob of internet business
| services.
| Linkd wrote:
| Squarespace is not 'tagged' in my brain under the "domain
| registrar" category yet. When I blindly think of domain
| registrars, as much as I dislike them, Godaddy is the first
| to come to mind.
| stronglikedan wrote:
| Squarespace positions themselves as a website builder more
| than a registrar. In fact, I doubt the average person would
| even realize they are a registrar, since that is abstracted
| away in the website building process.
| stronglikedan wrote:
| Correct. And the average person isn't aware of their "toilet
| of a reputation".
| apocalyptic0n3 wrote:
| This is the real key. They have an awful reputation amongst
| technical people (for good reason) but that reputation
| largely fades away the less technical you are. The average
| person knows them for their effective marketing, seemingly
| low prices, and seemingly decent products. They don't get
| into the weeds enough to expose how untrue those things
| really are.
|
| For a long time, I worked in an office across from their
| (now former) headquarters in the Scottsdale Air Park. The
| number of clients we had come in amazed that we must work
| so closely with them and expecting great things made the
| location of the office so invaluable that when they moved
| to Tempe and Chandler, we had to seriously discuss
| internally if we needed to follow them.
| palmfacehn wrote:
| They bought out another registrar I was a customer of. Now I am
| paying 40% more for renewals. If I want to migrate I need to
| expose my whois info. They're always looking to upsell me into
| some horrible hosting garbage.
| andybak wrote:
| They've bought up a whole series of services I was using and
| ruined them.
|
| Anyway. Nice to see the FTC getting a few wins in before they
| are defanged by the new administration.
| fraXis wrote:
| Can you temporarily change your whois info before you migrate
| to somewhere else?
| uxjw wrote:
| I've had some registrars lock the domain from transferring
| for a few weeks after changing whois.
| tredre3 wrote:
| It's called the 60 day registrant change lock. _Most_
| changes to administrative or technical contact
| information will trigger it.
|
| Although it's a real ICANN rule, the registrar is allowed
| to override it if they want. Of course very few
| registrars offer that kind of customer service, so that
| escape hatch might as well not exist...
| kachapopopow wrote:
| Update your whois to bogus information, transfer the domain,
| restore whois information. Cloudflare is the cheapest domain
| registrar long-term, you might get cheaper ones for the first
| year or first 3 years.
| RIMR wrote:
| Using bogus whois info is a great way to lose your domain.
| If you are afraid of exposing your phone number and
| address, rent a P.O. box and get a throwaway number to use
| in the interim.
| kachapopopow wrote:
| You will not lose your domain for having bogus
| information for 7 days. Having bogus information takes
| months of not an entire year to ever go through and the
| worst you will possibly get is a very stern warning to
| update your information or your domain will be taken
| away.
|
| I still have a .com domain that I've registered from when
| I was a child and I've just never bothered to update the
| information on it, the regulations on these are as lax as
| godaddys security.
|
| If you're a site with millions of views a day this might
| be different.
| kstrauser wrote:
| I don't use GoDaddy, but I had to transfer some domains of
| NetSol a couple months ago, and it made my experiences with
| GoDaddy look like a happy dream.
|
| People will put up with all kinds of awfulness if they don't
| know better.
| DonHopkins wrote:
| An unofficial ranking of the most NSFW GoDaddy commercials
| ever:
|
| https://www.golfdigest.com/story/an-unofficial-ranking-of-th...
|
| The Woman(!) Behind GoDaddy's Tasteless, Effective Super Bowl
| Ads:
|
| https://www.forbes.com/sites/jeffbercovici/2013/02/06/the-wo...
|
| Who Let These Commercials Be On TV?
|
| https://www.youtube.com/watch?v=_rRopnyZaR0
|
| GoDaddy's most infamous ads:
|
| https://www.youtube.com/watch?v=u7yFCqOAb9Y
|
| 10 SEXIEST GoDaddy Super Bowl Commercials - Sexy Super Bowl
| Ads:
|
| https://www.youtube.com/watch?v=4ECUIQv9ruo
| RIMR wrote:
| Hilarious to see all the takedowns on these videos. Who the
| hell DMCA's a reposted advertisement? It's literally free
| advertising. The only reason they would take these down is
| because they were ashamed of them - and they probably should
| be.
| ziddoap wrote:
| It's amazing that (approximately) no one cares about stuff like
| this.
|
| GoDaddy was severely breached several times over several years,
| yet they still rake in billions of revenue from their millions of
| customers. Now they have to pay someone to fill out a biennial
| checklist and... promise to not lie. Awesome.
|
| If you own a company, why even bother with security? Security is
| expensive. Wait until a breach is exposed, offer $10 credit
| monitoring (at best), accept the free press coverage, _maybe_
| pinky promise to not lie if you 've been particularly egregious
| in your handling of multiple incidents, and then carry on like
| normal. (This is tongue-in-cheek, I work in security, but I am
| frustrated with how often stories like this one occur)
| stackskipton wrote:
| >If you own a company, why even bother with security? Security
| is expensive. Wait until a breach is exposed, offer $10 credit
| monitoring (at best), accept the free press coverage, maybe
| pinky promise to not lie if you've been particularly egregious
| in your handling of multiple incidents, and then carry on like
| normal. (This is tongue-in-cheek, I work in security, but I am
| frustrated with how often stories like this one occur)
|
| As SRE, I've heard executives say this "There is no penalty for
| breaches, why care?"
| reaperducer wrote:
| _As SRE, I 've heard executives say this "There is no penalty
| for breaches, why care?"_
|
| Depends on the industry. I'm in healthcare, and our legal
| department is always reminding the devs that even a small
| breach can be financially catastrophic for the company, as
| they are totaled as $xx,000 per person affected.
|
| We get training on it every six months.
| stevenicr wrote:
| I'd like to hear more about this training -
|
| I have started to put together some resources to teach C
| suite, maybe new-to-the-field lawyers, other interested
| stakeholders - about website compliance issues..
|
| looking to mimic other good training / learning materials,
| extra info to consider, maybe collab and send business I
| can't take on, etc.
| ziddoap wrote:
| Not the person you are replying to, but I work in
| security and have spent ~5 years of my career helping
| various companies set up and maintain security awareness
| programs.
|
| There are some out-of-the-box solutions that can start
| you on your way to creating a security awareness training
| program, such as KnowBe4 and ProofPoint (there are others
| as well, but these are some of the big names). If you
| don't have in-house security staff, these types of
| offerings can be quite helpful.
|
| For a more grounds-up approach, there are guidelines such
| as the NIST SP 800-50 _" Building a Cybersecurity and
| Privacy Learning Program"_ guidance.
| (https://csrc.nist.gov/pubs/sp/800/50/r1/final)
|
| If you have specific questions, I can try to answer them.
| reaperman wrote:
| As a technically-minded person, I've found both KnowBe4
| and ProofPoint trainings to be very
| lacking/boring/superficial.
| ziddoap wrote:
| While I agree with you, that's why they are a starting
| point for someone looking to stand up a program, not an
| end point.
|
| And, from my experience, many of the trainings that seem
| almost offensively easy to me (e.g. "How to read a URL")
| have been some of the ones that received the most
| positive feedback from non-technical departments.
|
| The real key with security awareness training is ensuring
| the training is at the appropriate level of complexity
| for the trainee.
| transcriptase wrote:
| One way to relieve the boredom is to count the number of
| times you see the people in videos typing away on
| desktops/monitors with no cables plugged into them.
| infogulch wrote:
| So the answer is to put the same kind of onerous penalties
| that companies pay for leaking healthcare data and apply
| them to any PII / user data. If it can't hit the bottom
| line bigcorps don't care; liability is the only language
| they understand.
| reaperducer wrote:
| _So the answer is to put the same kind of onerous
| penalties that companies pay for leaking healthcare data
| and apply them to any PII / user data_
|
| Then you get people on HN shouting "regulatory capture!"
| and "stifling innovation!"
| infogulch wrote:
| Yeah it sucks, but what can you do when you have titanic
| amoral agents stomping through society? You gotta speak
| their language. Maybe scale the penalty with the size of
| the company.
| jjmarr wrote:
| You have to provide your email to sign up for HN,
| however, it is not publicly visible. If YCombinator had
| to pay $10,000 for leaking a user email, this site isn't
| going to exist since it's not their core business and
| represents a huge liability.
|
| It's also disproportionate. If my email is leaked in the
| context of receiving treatment for a stigmatized disease,
| that's a lot worse than an MMORPG leaking my real name.
|
| Maybe _some_ penalty is necessary but $10k or above per
| user is disproportionate for the vast majority of people.
| A $50 /person penalty with gradations for sensitivity of
| the information is going to work better in practice. If
| leaking an SSN is more expensive than an email or site-
| specific ID, corporations might stop using SSNs to
| identify people to reduce their exposure
| robertlagrant wrote:
| > Then you get people on HN shouting "regulatory
| capture!" and "stifling innovation!"
|
| You phrasing it like this is not a substitute for
| explaining why it wouldn't be those things.
|
| Also, the most obvious thing is: if you're a healthcare
| provider, you would probably hire some hackers to go
| after your competition, and let heavy-handed fines take
| them down. Much easier than providing better value.
| theoreticalmal wrote:
| Then I (a normal user) find myself in the position of my
| data being stolen/mishandled AND have to either pay for
| it via increase fees, or my healthcare provider goes
| belly-up and I have to find a new one.
| stackskipton wrote:
| Except Change Healthcare got hacked, lost a ton of records
| and they are still operating. So those fines must be, could
| be up to xx,000 per person affected but in actuality, those
| affected will get Arbys coupon and C Suite will lose a week
| of yacht time.
| kstrauser wrote:
| > As SRE, I've heard executives say this "There is no penalty
| for breaches, why care?"
|
| Honestly, I'm more afraid of reputational loss than
| government fines. Our customers don't _have_ to use our
| product. They do because they trust us. Lose that trust and
| it 's awfully hard to get it back.
| adrr wrote:
| Crowdstrike took down all windows boxes that had their
| software installed and didn't really affect them.
| jrochkind1 wrote:
| I think customers feel, rightly or wrongly, there's no
| alternative to CrowdStrike.
|
| There are so many alternatives to what GoDaddy provides,
| it is quite commoditized.
|
| But also... true, their customers don't seem to care
| anyway? Or it's "cost of switch", even just mentally? If
| you were starting fresh it really wouldn't be any harder
| at all to go with any of numerous alternatives, but if
| you already have godaddy...
| rez9x wrote:
| I've actually not worked anywhere that has used
| CrowdStrike. It's usually ruled out as too expensive
| (I've mostly worked in public sector). I've had very good
| experiences with Sentinel One and Microsoft Defender.
| I've had terrible experiences with Trellix and
| Sophos."Oopsy" aside, is CrowdStrike really that much
| better than the competition?
| alephnerd wrote:
| The big four (CRWD, S1, Prisma, and MDE) all mostly
| comparable tbh.
|
| EDR (especially Windows EDR) is heavily commodified.
| iforgot22 wrote:
| Crowdstrike's security reputation matters a lot more.
| I'll bet the customers assume the competitors have the
| same reliability problems, they can tolerate a little
| downtime, and going with nobody is even worse.
| manquer wrote:
| Yet.
|
| it takes time there are plenty of lawsuits flying around
| that incident .
|
| Even if they win all the suits without settling or
| loosing, customers will negotiate far stiffer penalties
| and controls on next renewal or get steep discounts or
| just straight up switch vendors .
|
| Sooner or later their ability to be competitive will get
| affected and they will likely become a target for
| acquisition and rebranding.
|
| Organizations of that magnitude do not collapse overnight
| like startups
| stevenicr wrote:
| I feel this is more important for a younger or smaller
| company, and less so when stopping a product from one
| company to switch to another is a pain in the ass or has
| other problems / risks..
|
| switching from godaddy to another registrar is not super
| hard, but there are hurdles and sometimes problems occur
| that even people with experience run into.
|
| I think (some?) people also hope a place that suffers a
| breach learns from it and makes it near impossible for
| similar to happen again.
| zelon88 wrote:
| Most customers use your product because it was on the first
| page of their Google search results.
|
| The only people who's reputation gets ruined are the
| D-Level Directors and Managers who run this stuff and
| regularly run into budget or resource shortfalls that
| prevent them from doing all that they are capable of doing.
| tsimionescu wrote:
| The whole thread is related to GoDaddy's numerous breaches
| not affecting their bottom line or market position. So it
| seems lots and lots and lots of people really don't care.
| philipov wrote:
| Creating lock-in which prevents customers from having an
| alternative is a more effective use of money, because it
| "solves" not just the threat of reputation loss due to
| security failures, but many others at the same time.
| ted_dunning wrote:
| Many people consider building a business on customer trust
| to be a strategic mistake.
| ToucanLoucan wrote:
| If you don't make the fines or whatever substantially more than
| the profit of the illicit or negligent conduct, it isn't a
| consequence. It's a budget line-item.
|
| Every regulatory agency in America has been stripped to the
| bones by decades of budget cuts and never ending accusations of
| "stifling innovation" and we're shocked now that companies get
| away with both metaphorical and actual murder.
| zelphirkalt wrote:
| They profit a lot from uninformed CTOs and founders just going
| for whatever they heard of, instead of looking into whether it
| is a good provider, footing their businesses on shaky
| foundations.
| reaperducer wrote:
| _They profit a lot from uninformed CTOs and founders just
| going for whatever they heard of, instead of looking into
| whether it is a good provider_
|
| If it wasn't for those old Super Bowl ads, GoDaddy wouldn't
| exist today.
|
| Sex sells.
| wswope wrote:
| Yeah - selection bias and apathy is the root of it, IMO.
|
| GoDaddy attracts the unwashed masses who don't care about
| security, and who remain unphased after learning about
| breaches. Meanwhile, the tech-savvy crowd who would care
| about breaches already know to avoid GoDaddy and view the
| inevitable breaches as the plebs reaping what they've sown.
|
| Ergo, no one getting breached by GoDaddy cares, and nobody
| informed watching it happen feels a need to intervene.
| DonHopkins wrote:
| The elephant in the room may be GoDaddy's historical total
| disregard for security, but hey, those pesky elephants won't
| shoot themselves!
|
| GoDaddy CEO's graphic elephant hunt video sends his clients
| flocking to competitors, and helps raise $20,000 for elephant
| charity:
|
| https://www.dailymail.co.uk/news/article-1374679/GoDaddy-CEO...
|
| GoDaddy CEO Kills Elephant:
|
| https://www.youtube.com/watch?v=YnM5yTW2B3g
| runnr_az wrote:
| Bob hasn't been CEO of GoDaddy since 2011
| DonHopkins wrote:
| I know, that's exactly why I wrote "historic", but the
| current owners gave him an enormous amount of money, didn't
| clean up their act, and GoDaddy CONTINUES to be terrible.
|
| The security breach we're discussing didn't happen 14 years
| ago, as you well know. They have a long and infamous track
| record and toxic corporate culture and unethical business
| practices and willfully misleading negligence of security
| that show no signs of improving.
|
| So charming that you're on such a familiar first name basis
| with a piece of shit like Bob Parsons. Are you friends? Are
| you actually carrying the water for GoDaddy, or think it's
| ok to murder elephants and run incredibly sexist
| commercials while never giving a shit about security or
| customers? Yuck.
| retrochameleon wrote:
| They are also the worst hosting provider I have ever worked
| with, multiple times. Awful customer support and high prices.
| The only reason I work with them anymore is to migrate new
| customers to a different provider.
| gtech1 wrote:
| So basically like Microsoft ?
| overstay8930 wrote:
| Most companies are way too incompetent to even know how to
| secure their own data because it is just too expensive to
| actually hire someone that knows what they're doing - so most
| of the "cybersecurity" industry is just grifters talking about
| buzzwords and building dashboards to show how good they are at
| patching CVEs.
|
| I have had to tell multiple cybersecurity vendors that brag
| about working with huge companies and governments that we
| cannot work with them because of how poor their own
| cybersecurity practices are (i.e. not using secure
| compute/hardware crypto when dealing with our private keys).
|
| These are companies that should know better, I have had to stop
| ADP professional services more than once from disabling
| certificate validation on critical pipelines pertaining to
| confidential employee and customer information. I do not want
| to imagine what happens at 99% of companies with cybersecurity
| teams that don't even know what certificate validation is.
| dustywusty wrote:
| The sad truth is that for the most part, the web hosting
| industry has normalized a fairly lax approach to security, and
| sees settlements like this, and even breaches, as a cost of
| doing business. Look at Wordpress maintenance, for example.
|
| It's a tough business hosting arbitrary UGC, and doing it well
| costs a lot of time effort and money (ask me how I know). But I
| fully agree: treating this as just another line-item cost is
| absurd.
| wsatb wrote:
| GoDaddy had really good marketing at one point and as of the
| last time I used it, which was years ago, they make it very
| difficult (I'm pretty sure by design) to leave. Their UX was
| one of the worst I've ever experienced in my life and they were
| consistently moving things around to make it worse. They
| essentially trap you, and someone without either the savvy or
| diligence will just give up.
| tkems wrote:
| I was shocked when I purchased a domain recently on GoDaddy (I
| normally use Cloudflare or AWS) and noticed that they have an
| 'upsell' with more security options (MFA and some other features)
| for something like $10/yr. Why wouldn't they want their customers
| to be more secure by default? To me it just reeks of money-
| grabbing for people that are none the wiser.
| grajaganDev wrote:
| It is outrageous and irresponsible to charge for MFA.
|
| It show a cavalier attitude toward the greater security of the
| internet.
| Terretta wrote:
| Same for OIDC (and even traditional SAML SSO).
|
| If every stolen or potentially stolen credential was billed
| to the breached provider at even $100/account*, SSO would
| become free so fast your head would spin.
|
| Every credential in the provider's DB would be correctly seen
| as a liability.
|
| * Arguably the number should be higher and contribute to a
| infosec response, detection, and preventative measures
| warchest. Though, ultimately, this would probably just enrich
| cybersecurity insurance firms.
| grajaganDev wrote:
| Agreed.
|
| Another example is Microsoft charging extra for enhanced
| logging. This came to light during the SolarWinds debacle.
| insane_dreamer wrote:
| I can't believe GoDaddy is still in business. Shows you can be a
| horrible company -- borderline scammy back in the day -- and
| somehow survive.
|
| FWIW we've used Gandi for years and very happy with it.
| thinkingtoilet wrote:
| The power of advertising and first-mover advantage. Outside of
| the tech space, people really only know of godaddy if they want
| to buy a domain.
| msikora wrote:
| Marketing and large captive audience.
| josefresco wrote:
| If you think GoDaddy is _the most_ terrible, you have never been
| exposed to the hell that is Network Solutions.
|
| GoDaddy is big, safe and terrible. Network Solutions is big, safe
| and even worse.
| nnf wrote:
| I can't pass by this comment about Network Solutions without an
| enthusiastic second. Several times per month I help various
| customers with their domains, and when I see that one is with
| Network Solutions, I know I'm going to have to waste a bunch of
| time with their _terrible_ DNS editor and will have to wait
| around for at least 20 minutes before their own editor reflects
| the changes I 've made.
|
| The worst part is that when replacing an A record with a CNAME,
| it lets you delete the A record but then blocks you from adding
| the CNAME, because "a record with that name already exists"
| (referring to the one that was just deleted). This is where the
| 20+ minute wait changes from "inconvenient" to "downtime". It's
| been like this for at least 15 years.
| ivoflipse wrote:
| In related news, their ISO 27001 certificate just expired. Seems
| in line with their overall security posture then
| https://img1.wsimg.com//Sitecore/6/1/registrar-iso27001-cert...
___________________________________________________________________
(page generated 2025-01-28 23:00 UTC)