Quote:
Originally Posted by Alexander Turcic
Dennis, I understand what you're saying. Still, it's not an excuse for not notifying their customers as soon as they found out about the hack attempt. Even if they had to disconnect their infrastructure from the Net, they could have accessed their mailing list internally and sent out the mails using their external provider.
|
Could they?
We don't know what their setup is, nor how many warm bodies they had to work on the issue. It might have been a case of "We can work on determining how the site was hacked, what the exposure is, putting fixes in place to prevent a recurrence, and getting the site back on line and accepting revenue,
or we can work on extracting the user list, generating an email explaining things, and forwarding it through NS. We don't have the resources to do both at once. Which is more important?" Betcha management would say "Getting the site back up and generating revenue"...
______
Dennis