← Back to context

Comment by Arnt

7 hours ago

Uh, is that what they did? I didn't read their blog posting like that. But let's put that aside and focus on something else. How was it a failure of internal practice, what did they do wrong?

AIUI they used a proxy with a bug, which they reported as soon as they discovered it. Right? What should they have done, and what's the difference?

Monitoring that didn't take days to notice unauthorized external traffic would probably be a good start