Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

can someone please make a hall of shame for all the big Companies which where hacked! i think there are quite a lot by now.


It shouldn't be a hall of shame for companies being hacked, getting hacked is thing you can only mitigate not prevent.

The shaming should be for storing your sensitive data in an insufficiently secure manner. If a company used scrypt to hash their passwords then they would essentially have no issue with getting hacked.



This would just lead companies not to disclose cases, which would be far worse for everybody.

Openness about this kind of thing should be encouraged.


Hacking is inevitable.


While 0-day vulnerabilities will always get the best of some companies, there are some security breaches that are just due to plain negligence of the company.

I believe I recall Sony getting hacked, and tons of plain-text credit card numbers were hacked. It was discovered that Sony didn't even follow even the most simple of PCI compliance.

It's things like that that deserve the "hall of shame"


I have a PSN account and indeed had an account during that event. There was tons of wild speculation about what data was breached, but there was no evidence that credit card numbers were included. Sony unfortunately only fueled those rumors by refusing to comment on the specifics, but I can assure you that if they were storing "tons of plain-text credit card numbers" there would have been a legal shitstorm the likes of which we have not seen in many a year, including a class-action lawsuit. I have yet to receive any invitations to participate in any such lawsuit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: