Why ‘blaming the intern’ won’t save startups from cybersecurity liability – TechCrunch

-


SolarWinds is back in hot water after a shareholder lawsuit accused the company of poor security practices, which they say allowed hackers to break into at least nine U.S. government agencies and hundreds of companies.

The lawsuit said SolarWinds used an easily guessable password “solarwinds123” on an update server, which was subsequently breached by hackers “likely Russian in origin.” Former SolarWinds chief executive Sudhakar Ramakrishna, speaking at a congressional hearing in March, blamed the poor password on an intern.

There are countless cases of companies bearing the brunt from breaches caused by vendors and contractors across the supply chain.

Experts are still trying to understand just how the hackers broke into SolarWinds servers. But the weak password does reveal wider issues about the company’s security practices — including how the easily guessable password was allowed to be set to begin with.

Even if the intern is held culpable, SolarWinds still faces what’s known as vicarious liability — and that can lead to hefty penalties.



Source link

Ariel Shapiro
Ariel Shapiro
Uncovering the latest of tech and business.

Latest news

How Claude Code Is Reshaping Software—and Anthropic

Engineers in Silicon Valley have been raving about Anthropic’s AI coding tool, Claude Code, for months. But recently,...

ICE Agents Are ‘Doxing’ Themselves

Last week, a website called ICE List went viral after its creators said that they had received what...

Crypto Bill Delayed As Senate Pivots To Housing Initiatives

The sweeping U.S. Senate effort to establish a comprehensive legal framework for cryptocurrency trading and oversight...

Google Acquires Top Talent From AI Voice Startup Hume AI in Licensing Deal

Google DeepMind is hiring the CEO and several top engineers from Hume AI, a startup working on emotionally...

A Wikipedia Group Made a Guide to Detect AI Writing. Now a Plug-In Uses It to ‘Humanize’ Chatbots

On Saturday, tech entrepreneur Siqi Chen released an open source plug-in for Anthropic’s Claude Code AI assistant that...

The WIRED Guide to Two-Minute Mantra-Less Meditation

Launching straight back into work in the New Year can be challenging, but learning how to meditate can...

Must read

You might also likeRELATED
Recommended to you