• InnerScientist@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    1 day ago

    Just great.

    Obviously the customers don’t need to know that their audit logs not only could have been turned off for conversations without any extra authentication, but also are so easy to turn off that it happens by accident without any extra intervention.

    Also their entire Vulnerability disclosing guideline is security/compliance/image theater.

  • scytale@piefed.zip
    link
    fedilink
    English
    arrow-up
    14
    ·
    1 day ago

    That’s gonna be a bunch of security and compliance violations, not to mention messing with incident response and digital forensics.