The order comes after discovering years of inadequate protection measures that left millions of websites vulnerable to attacks.
The FTC found that GoDaddy failed to implement basic security measures to protect its +5M hosting customers, resulting in multiple major security breaches between 2019 and 2022.
FTC: “GoDaddy’s data security program was unreasonable for a company of its size and complexity. Despite its representations, GoDaddy was blind to vulnerabilities and threats in its hosting environment.”
The settlement requires implementation of new security measures and regular 3rd party monitoring. Future issues could result in penalties of more than $50K for each violation.
1 thought on “Business Roundup Week Ending January 24”
Worth noting is that GoDaddy has owned a major web security provider, Sucuri, since 2017. This gets ignored despite GoDaddy probably profiting off of selling security services in response to security problems they created. And despite the reasonable questions as to Sucuri’s security competency when their parent company has such bad security, the US government got involved.
That issue ties in the first news item, as the original source for the “stealth” malware claim is Sucuri. This isn’t actually a new issue. Hackers have long placed malicious code in the database. It isn’t hard to detect. That Sucuri thinks it is stealthy isn’t a great sign of their competency either.
Worth noting is that GoDaddy has owned a major web security provider, Sucuri, since 2017. This gets ignored despite GoDaddy probably profiting off of selling security services in response to security problems they created. And despite the reasonable questions as to Sucuri’s security competency when their parent company has such bad security, the US government got involved.
That issue ties in the first news item, as the original source for the “stealth” malware claim is Sucuri. This isn’t actually a new issue. Hackers have long placed malicious code in the database. It isn’t hard to detect. That Sucuri thinks it is stealthy isn’t a great sign of their competency either.