Liberty SMS - Unauthorized access to IT infrastructure

No doubt. I imagine that's usually the order of things in these situations. Again, all I was asking for was something more than "I heard through a colleague or friend".

They were breached Thursday. Their clients found out about it on Sunday morning. Factually reported.

“This occurred on Thursday evening. It took a couple of days before deciding we should inform customers and ensure that we can safely move into the public domain, as it is a complex matter.”
Too many times GENERALLY, as is the unfortunate track record throughout the world, when a sad event such as this occurs, the prevalent action seems to be to first look at potential fallout and see if it will quietly go away, etc.
But in these times, the info gets online so fast, heads completely spin.
We are in no way inferring this was intentionally done, yet rather using the historic corporate track record of going public with such breaches, what else is left for the public to go on?

Also, back to one of the other questions I had...
So you do not have first hand experience with Liberty or work for a company with first hand experience of Liberty's systems?

Nope, but seeing as this seems to be hitting a nerve of sorts, and the bit of industry experience some of us here have is not washing, I offer to you that you are right, and Liberty did all they could and their systems are perfect.
 
They were breached Thursday. Their clients found out about it on Sunday morning. Factually reported.
So? You have an issue with this for some reason, please explain. I assume the event on Thursday was the communication received from the perps.

petec said:
Too many times GENERALLY, as is the unfortunate track record throughout the world, when a sad event such as this occurs, the prevalent action seems to be to first look at potential fallout and see if it will quietly go away, etc.
But in these times, the info gets online so fast, heads completely spin.
We are in no way inferring this was intentionally done, yet rather using the historic corporate track record of going public with such breaches, what else is left for the public to go on?
OK, so pure speculation. I assume they had to verify the information they received on Thursday that there was indeed a breach. This likely took time. Why would anyone want to damage their business and shareholders interest based on speculation? You verify these things including the extent of the breach. Notifying clients is then done if necessary, which they did - over a weekend.

Nope, but seeing as this seems to be hitting a nerve of sorts, and the bit of industry experience some of us here have is not washing, I offer to you that you are right, and Liberty did all they could and their systems are perfect.
:erm: OK. I was quite clear on that point and no, there's no arguing that point for anyone's systems. None of this is about making Liberty out to be perfect, all I'm trying to do is establish fact. You appeared to suggest that you had worked at Liberty and advised them of vulnerabilities that they never attended to - I was trying to establish the facts in your statements... it's quite a serious point if factual.
 
Last edited:
“This occurred on Thursday evening. It took a couple of days before deciding we should inform customers and ensure that we can safely move into the public domain, as it is a complex matter.”

This course of action is a two way street as far as the public is concerned, with historically there being a lot of instances where affected parties hope the sordid affair just goes away.

This is a public forum, where we discuss on facts at hand, as well as relevant experience and subsequent opinion. This is the nature of discourse and vigorous debate.

However, when shared opinion is derided, and demands are made by those who also seem to not have implied credentials, then all it boils down to is "I dig Liberty! They RuL3z and you $uX0rZ!"

Shrug whatever... The truth always outs in any event.
 
GDPR requires them to do that if they didn't put enough security in place. This is not them being open and public, this is them coming short on securing your data.

So GDPR is an EU thing and not a SA thing. So there is no legal requirement for them to do it. Yes you could argue they have clients who may now reside in the EU but this is a South African legal entity.
Email is not secure and the hackers gained access to an email type system.
 
You appeared to suggest that you had worked at Liberty and advised them of vulnerabilities that they never attended to - I was trying to establish the facts in your statements... it's quite a serious point if factual.

I never implied that in any form. I said that this has been going on for years, in the industry as a whole, with there being a disconnect between those wanting to fix security issues, and those who don't deem the issue as serious as it actually is.

If you inferred that I worked there and had inside info, that is something I have no control over.
I responded a few times that I don't work there, not am I involved with their systems in any shape of form.
Only a fool would come on to a public forum and splash around, if they were directly involved.
I have no such contracts or employ.
 
So GDPR is an EU thing and not a SA thing. So there is no legal requirement for them to do it. Yes you could argue they have clients who may now reside in the EU but this is a South African legal entity.
Email is not secure and the hackers gained access to an email type system.

GDPR reaches far outside the EU, SA needs to comply.
 
They were breached Thursday. Their clients found out about it on Sunday morning. Factually reported.

“This occurred on Thursday evening. It took a couple of days before deciding we should inform customers and ensure that we can safely move into the public domain, as it is a complex matter.”
Too many times GENERALLY, as is the unfortunate track record throughout the world, when a sad event such as this occurs, the prevalent action seems to be to first look at potential fallout and see if it will quietly go away, etc.
But in these times, the info gets online so fast, heads completely spin.
We are in no way inferring this was intentionally done, yet rather using the historic corporate track record of going public with such breaches, what else is left for the public to go on?



Nope, but seeing as this seems to be hitting a nerve of sorts, and the bit of industry experience some of us here have is not washing, I offer to you that you are right, and Liberty did all they could and their systems are perfect.

Have you Listened to the press conference last night, links in Thor post in this thread?

First Liberty had to assess whether the threat was real or a hoax.
Engage with authorities.
Engage with IT, Vendors and other third parties.
Ensure you are on top of the situation and know where you stand.
48 hours is not bad going to be in a place to make this public.
 
This is a public forum, where we discuss on facts at hand, as well as relevant experience and subsequent opinion. This is the nature of discourse and vigorous debate.

However, when shared opinion is derided, and demands are made by those who also seem to not have implied credentials, then all it boils down to is "I dig Liberty! They RuL3z and you $uX0rZ!"
Asking you to back up your statements is a reasonable part of debate.
 
I never implied that in any form. I said that this has been going on for years, in the industry as a whole, with there being a disconnect between those wanting to fix security issues, and those who don't deem the issue as serious as it actually is.
Reminder...
No I don't work there.
But what irks me, is the initial denial from Liberty, as well as the fact, that this has been going on forever.
Like back in the day when we easily copied the SAM file and then showed the powers that be that their belief that their systems were "Ho ho ho, unbreakable" was a delusion.
For us to walk up to unsecured systems and be able to do these things, and then be told that measures to fix were way beyond budget, was mind boggling.

If you inferred that I worked there and had inside info, that is something I have no control over.
I responded a few times that I don't work there, not am I involved with their systems in any shape of form.
Only a fool would come on to a public forum and splash around, if they were directly involved.
I have no such contracts or employ.

What else are we to assume from your bolded post? You refer to Liberty denying that this happened then straight into a sentence that says "Like back in the day when we easily copied the SAM file and then showed the powers that be that their belief that their systems were "Ho ho ho, unbreakable" was a delusion."
 
Last edited:
Really? How so?

As soon as you have even one customer residing in the EU.

If you don’t comply, your board can be deemed delinquent and have criminal charges against them.

In addition of fines on the worldwide turnover and suspension of their insurance/banking licenses in the EU (that could be annoying for Liberty and its relationships with reinsurers for example).

https://diligent.com/wp-content/uploads/2017/11/WP0032_US_The-GDPR-Checklist-for-Directors.pdf
 
As soon as you have even one customer residing in the EU.

If you don’t comply, your board can be deemed delinquent and have criminal charges against them.

In addition of fines on the worldwide turnover and suspension of their insurance/banking licenses in the EU (that could be annoying for Liberty and its relationships with reinsurers for example).

https://diligent.com/wp-content/uploads/2017/11/WP0032_US_The-GDPR-Checklist-for-Directors.pdf

I can't open the link from work, but I would qualify that statement. If you do business in the country I would say yes - but if you have a foreign national that buys a local product, then no.
 
As soon as you have even one customer residing in the EU.

If you don’t comply, your board can be deemed delinquent and have criminal charges against them.

How is a local company, who doesn't operate in the EU, going to be charged criminally here in SA?
 
How would you enforce it?

Go read post #154 again.

Criminal liability for directors, fines, suspension of all licenses (Liberty has offshore funds in the EU, probably some kind of banking/insurance license, reinsurers...).

You can cripple a business.
 
Go read post #154 again.

Criminal liability for directors, fines, suspension of all licenses (Liberty has offshore funds in the EU, probably some kind of banking/insurance license, reinsurers...).

You can cripple a business.

And again I ask, if the directors reside in SA, how would you criminally prosecute them? And if they have licences in the EU, then they are operating in the EU, which is a point I agreed on.
 
Top
Sign up to the MyBroadband newsletter
X