5 ms·
It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility th
by addingnumbers 4y ago
It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected.
This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.
- sangnoir 4y agoHow can anyone make any assertions about unknown unknowns? It's one thing to say "My car was stolen", and another to declare "I am unable to determine if it's en route to the Taliban."
- Lutger 4y agoIts not an unknown unknown. If there's a vulnerability and you're a hot target, you know there's a decent chance of getting exploited.
- upsidesinclude 4y agoThat isn't a reasonable analogy in any way. The only thing that could happen with the data would be that it is exploited. The only thing that happens to stolen cars is not going to the taliban. These are not even similar in nature. They aren't saying "the data was stolen". They also aren't saying "the data was available for exploit we are unable to determine if that occured." What if they never looked for evidence of unauthorized access? They wouldn't have any! This is the same as modern science and medicine frequently using this academic phrase, no evidence, when what they mean is that there has been no investigation.
- execveat 4y agoYou can make positive assertions though. E.g. attack might have been simple in which case it's possible to produce indicators that cover 100% of variants. Or it could have been complex and indicators either don't cover every possible attack or they produce large number of false positives. Another thing to mention would be how long in the past you were able to look. E.g. in this case they have found out that the bug was introduced in 2021, were they able to inspect logs covering all of that period or did they only had limited logs/other evidence so it's impossible to know whether anyone used this opportunity or not?
- autoexec 4y agoIt's more like saying "I left my car in a shady neighborhood unattended for 72 hours with the doors open and the key left in the ignition but I haven't been keeping track of the millage or the fuel level so I'm not aware that anyone used it while I was away." Nothing would have stopped someone from using it. Probably best to assume that they have.
- dumbfounder 4y agoHow about we don’t use terse language and a short blog post to describe a complex thing and instead talk about what happened, what you did to investigate, WHY you couldn’t determine if it was exploited, and what the heck you intend to do about it? How about some facts and transparency? How about some real honesty?
- Sebb767 4y ago> instead talk about what happened, what you did to investigate, WHY you couldn’t determine if it was exploited, and what the heck you intend to do about it? This will be read by optimistically 1% of people, the rest will just catch the summary. This way, you at least get to write the summary.
- TecoAndJix 4y ago"At this time, there is no obvious evidence of malicious activity"