JD Group confirms data breach

I'm convinced you're making a point somewhere in there.
Ok... it was very concisely put.

Assume you don't disagree with the first statement. You can have competition, and still not have open competition.

Do you agree with the premise, in the second? i.e.

The only training needed is how the West turned the tables on their overlords, and then promptly fell asleep at the wheel ala Jefferson's eternal vigilance.

That is to say, free markets, or the push for them, were a new thing, which lasted a few hundred years, and are now all but dead going back the last 100 - 120 years.

Jefferson, on keeping watch over the State/centralization of power: 'the price of freedom is eternal vigilance'
 
Data was likely taken by an IT staff member from the inside and given to a third-party back in 2020. Agreed, this is not recent data nor is it live data.
I'm looking at it, its definitely not new. It doesn't look like SQLi because 1. its not all the data and 2. missing the structural info sqlmap and friends would have dumped. (unless they cleaned it up)

I did notice that they did include a link on one of the boards to a PHP file on the jdgroup site, i'm wondering if they weren't highlighting the vulnerable entry point.
 
I'm looking at it, its definitely not new. It doesn't look like SQLi because 1. its not all the data and 2. missing the structural info sqlmap and friends would have dumped. (unless they cleaned it up)

I did notice that they did include a link on one of the boards to a PHP file on the jdgroup site, i'm wondering if they weren't highlighting the vulnerable entry point.

Agreed. You will also notice that only about 30k of those entries had contact information and addresses. The rest only names and email addresses. I think they only mentioned the JDG group to highlight the source of the data. I doubt any of this data is housed on their server.
 
Agreed. You will also notice that only about 30k of those entries had contact information and addresses. The rest only names and email addresses. I think they only mentioned the JDG group to highlight the source of the data. I doubt any of this data is housed on their server.
Yeah the actual enrichment is bad, a lot of data missing.
 
Ok... it was very concisely put.

Assume you don't disagree with the first statement. You can have competition, and still not have open competition.

Do you agree with the premise, in the second? i.e.



That is to say, free markets, or the push for them, were a new thing, which lasted a few hundred years, and are now all but dead going back the last 100 - 120 years.

Jefferson, on keeping watch over the State/centralization of power: 'the price of freedom is eternal vigilance'
You'll have to put it in context for me.
 
Ah, the blame the pilot defense. That is always a last ditch crutch to assists the aircraft network firewall manufacturers from still making billions.
You don't believe in a holistic approach to security? You're of the opinion that technology is the only defense?
How is your technology going to stop me letting my anyone else use my work machine while it has access to sensitive data?
 
the Chinese pay better, okay @r00igev@@r , how would you fix this?
is it even possible with the ATP threats out there.
What I think is missing is a solution strategy. I see that many companies have limited structure to the architecture and no continuous improvement initiatives. There are companies still running flat networks with Cisco 6509s.
Just like Eskom every company in South Africa has been sweating its assets and that comes at the cost of a breach. Its like when you have poo on the lawn, flies are sure to rock up.
 
You'll have to put it in context for me.
Ok. Let's start at the beginning, then.

Do you think open competition is :

a) a nice-to-have, or

b) a necessary ingredient

for/to achieve a flourishing civilization.
 
What I think is missing is a solution strategy. I see that many companies have limited structure to the architecture and no continuous improvement initiatives. There are companies still running flat networks with Cisco 6509s.
Just like Eskom every company in South Africa has been sweating its assets and that comes at the cost of a breach. Its like when you have poo on the lawn, flies are sure to rock up.
a retail group isn't a Bank or a defense contractor like Lockheed martin, a Retail group has different resources than those 2,
so many companies do the best they can do, work as hard as they can and hope its good enough.

you cant protect everything, that's simply impossible.
 
You don't believe in a holistic approach to security? You're of the opinion that technology is the only defense?
I am of the opinion that without correct causation you cannot blame either humans or technology.
Its a fallacy to believe you can close the gap on a technology deficiency by using a human. If a human was good enough you would need no technology. If the technology was good enough you would need no human.
Humiliating the human because they clicked on a phishing link while hungover isn't the answer, esepcially when you as a company, as an example, haven't implemented DMARC and use 8.8.8.8 as your DNS.
 
I am of the opinion that without correct causation you cannot blame either humans or technology.
Then why did you jump on the Fortigate bashing tangent?
Its a fallacy to believe you can close the gap on a technology deficiency by using a human. If a human was good enough you would need no technology. If the technology was good enough you would need no human.
Technology will always be deficient. What now?
Humiliating the human because they clicked on a phishing link while hungover isn't the answer, esepcially when you as a company, as an example, haven't implemented DMARC and use 8.8.8.8 as your DNS.
There are loads of ways insiders can be a threat, negligence is just one. Tech is a tiny part of the solution. Nobody's blaming your SD-WAN solution for being insecure here.
 
a retail group isn't a Bank or a defense contractor like Lockheed martin, a Retail group has different resources than those 2,
so many companies do the best they can do, work as hard as they can and hope its good enough.

you cant protect everything, that's simply impossible.
Pull the other one. The richest people in the world owned retail groups.
 
a retail group isn't a Bank or a defense contractor like Lockheed martin, a Retail group has different resources than those 2,
so many companies do the best they can do, work as hard as they can and hope its good enough.

you cant protect everything, that's simply impossible.
Agreed, BUT,

Hence my rants previously.

This gets outsourced to different places as no one can do the job. "Everyone can do IT, yet no one can do IT". Like most experts they can hyperlink Google searches and "fix" issues, yet they don't understand the technology.

Like Microsoft disabling basic authentication and implementing OAuth 2.0. What a ****up that has been.

But yeah outsource your IT where it eventually ends up with me, not a team, just me.

I need to fully understand everything, yet I am waiting for the day it all comes crashing down.

Oh your mail is not sending. Let me check, oh the application can only send internally. Let me send you the documentation on Exchange. Oh you dont understand it, let me do it.

"Hey ****, funny story, while you are fixing the customers exchange, my dog pissed on my keyboard, please fix asap. But it is important as I have a meeting in 30 minutes".

Like I said last time, not sure why I dont do house chores for the team even. Need to pick up their dog **** as well. Maybe teach their kids as well.

Come Monday, I hope I had enough time to study for the new Microsoft technologies.

Long story short. Hope this never happens to me.
 
Pull the other one. The richest people in the world owned retail groups.
so according to you data breaches are because companies didn't spend majority of their profit on cyber defense?
most people aren't the NSA with a limitless resources, most companies have dozens of other items to pay off, so they do the best they can and hope thats enough.
 
Long story short. Hope this never happens to me.
its never nice, but again with the fragmented nature of IT that talented people are working for 15 different contractors, that none of them know whats really going on
AND the limited budgets they have to work with,

and the scarcity of skills

what exactly can people do? not much if you ask me.
you do the best you can with what you have.
 
so according to you data breaches are because companies didn't spend majority of their profit on cyber defense?
most people aren't the NSA with a limitless resources, most companies have dozens of other items to pay off, so they do the best they can and hope thats enough.
Yeah I don't recall Integr8IT having a Cyber defence team either.

So when companies like sa tourism outsourced their IT to them, how much was actually maintained.
 
Top
Sign up to the MyBroadband newsletter
X