And you think those other sites are more secure? The differences are slight. Giant public websites are tricky. It is very hard to deploy real security across such a large team/platform. Even if you make the effort, some security measures simply wont fly, especially in regards to change control or network segmentation. This sort of bug is only one level of the issue.
Open up any random NIST, ISO or even PCI doc to see what is involved above and beyond bug squashing.
And that would have been covered under nist or iso or any other resonable standard. My point is that once you look into these companieas, get beyond the tech stuff, virtually none implement proper security on such large deployments.
Well, without ndas make it hard to find actual reports, but take ashley-madison. Millions of users, talk of a billion-dollar ipo, and the post-hack report by the canadian and austrailian privacy ministers found they had no formal security plan.
No.. working as a compliance attorney, along with all the industry contacts that entails, allong with a steady stream of reports such as the OP (also target et al) gives me grounds to say that proper security is not an industry norm, that the opposite is more likely.
In doubt? Ask around for how many organizations have a dedicated ciso or privacy officer.
Lol, that is like 1% of the industry. For every facebook there are 100s of smaller shops with websites taking money and handling pii. Being not-facebook doesnt mean you arent in the big leagues with millions of customers.
And that 1% of the industry is exactly the context for these comments, the company being discussed here is Yahoo. I guess you didn't read the part where I specified "SV tech giants"?
Open up any random NIST, ISO or even PCI doc to see what is involved above and beyond bug squashing.