[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Cobalt to provide compensation for server hack?



> >Has anyone taken up the issue of compensation for this incident with
> >Cobalt? Surely they must be liable as they failed to provide sufficient
> >server protection. We had all patches loaded and security was still
> >compromised.
>
> You are kidding right ? Do you sue an auto maker because you locked your
car
> but, it was still stolen ? What protections (firewalls, IDS, etc) did YOU
> build into your network ? I think the due diligence falls on your company,
> for protection of the network.



this is a very interesting question.  by default, cobalt offers
very little to no advice on how to protect the product from attacks,
which is 100% part of the reality of having a server connected to a
full-time hi-speed network.

it's a bit like telling kids they can take their razor scooter and
ride it down the freeway with the grown ups.. but not offering them
a helmut, or a bright orange flag that screams "hey go easy on me,
i'm just learning about this freeway thing"

perhaps cobalt was realising these difficulties, and this was part
of the reason that the sun acquisition went ahead.  get the money
and leave the real problems to someone else.