For example, the financial companies I used to work for had a “standard practice” of archiving all e-mails and internal chats for 7-8 years. Not sure if phone calls on company equipment were recorded or retained though (may be a YMMV case).
This is why I separate work and personal assets. I never do work on personal devices nor do I use work devices for personal activities (ie, social media, e-commerce, shit posting). Also if I’m shit talking the boss’s boss. It’s never using work devices.
Have been asked a few times to use personal devices for work but absolutely refused. I would be asked to install their invasive spyware and root kits so they can abide by their draconian corporate policies. So far, they haven’t forced me otherwise I would have quit those companies long ago.
The shining poster boy for this would be Google, who told staff to disable logging when discussing sensitive topics:
https://www.techspot.com/news/102874-doj-alleges-google-dest...
They also told employees to never use certain keywords, so that records of conversations would not be found by legal teams using search tools, but also they wouldn't be shown talking like monopolists:
https://arstechnica.com/tech-policy/2023/09/google-hid-evide...
Do any large companies not delete everything at the first opportunity?
(ComfyUI_LLMVISION is probably what caused this breach)
1) There are very few consequences. At worst, a hacker will get 5-7 years, and the chance of getting caught is low.
2) Security is very very very hard. The defender must get everything right. The attacker only needs to find one flaw.
3) Security does not just depend on security staff. It depends on every software engineer, operations (or devops) engineer, every software dependency, every piece of hardware, etc. If one of these people or dependencies has a problem, the whole system can be cracked. Examples of problems include writing insecure code, getting hacked, not removing old employees from an ACL or group, installing a tool with a back door, etc.
The point is security is hard and it depends on people doing the right thing. It's very hard to get people to do the right thing.
Maybe a dumping tool that uses a stolen api key? Rate limiting and monitoring on slack’s part could help…
Not sure why they would dox him, maybe to throw him under the bus after he found out he got pwned and cut them off?
Disney doesn’t just use one Slack instance across the whole company and everyone knows to not put pre-release content on my public platforms.
Maybe they compromised an instance owned by DTSS (Disneys centralized IT entity), but this would have little to do with Disney Studios like they imply.
Its pretty standard in the industry to only store pre-release content on airgapped systems.
It will be interesting to see what happens here. Information that leaks could actually impact share price.
I can’t guard the front door effectively.
Nor, I can easily guard the back doors.
Will data breaches like these: AT&T, Ticketmaster, and now Disney—-a nail in Security coffins for SaaS?
so all of those basics are going to magically happen when you move your data on-prem?
I don't know why but I find this funny.