• PushButton@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    17 hours ago

    Didn’t they just said, not long ago, that security would be their “top priority”.

    Same old story; the hand doesn’t follow the mouth.

  • Encrypt-Keeper@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    2 days ago

    In the last few years we used to do windows updates quarterly on our production servers as required by PCI DSS. In the last year though, we’ve had to do updates every single month due to critical CVEs needing to be patched. It’s becoming ludicrous actually, yet they’re cutting security folk.

    • Evotech@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      17 hours ago

      Think we patch monthly regardless in and outside of PCI scoped environments. The issue recently is that customers want even more frequent patches, like within a few days of the CVEs

  • MajorHavoc@programming.dev
    link
    fedilink
    English
    arrow-up
    37
    ·
    2 days ago

    It’s pretty important to me to not turn to a life of crime, but I appreciate everyone laying off their security teams, and putting all their most valuable data in one place, just in case I should change my mind…

    I’m not going to change my mind, but it’s awfully considerate anyway.

  • Ephera@lemmy.ml
    link
    fedilink
    English
    arrow-up
    26
    ·
    2 days ago

    Fucking hell, man, with how many very publicly visible security problems they had last year, you’d think the stakeholders would be on board with doing security for a bit.

    • psmgx@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 days ago

      Stock price is still way up compared so 2022, security issues notwithstanding. Why fight battles that won’t impact the bottom line?