Hacker News new | past | comments | ask | show | jobs | submit login

Still, I would have thought it is good practice to notify your users if you leak their data to thieves. Quora did the right thing and should be applauded.

As a counterexample, it seems that Newegg had a massive breach (thieves installed JavaScript that skimmed credit card numbers for weeks) in August, and even though my credit card was likely stolen, I hever heard about it from Newegg.




Not sure why you didn't hear from Newegg, but they did send out a mass email notification with details of the breach.


I somehow got their email a week or so after the event, and after my card's fraud prevention called for suspicious activity, reverted the transactions and cancelled my card. The bank official was not aware of the leak.


They did? I never got anything from them. And I was definitely within the time window.


How did you find out they did that? Just following tech news?





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: