GoDaddy was ordered to strengthen security measures

Industry News
28 Jan 2025 01:33:34 PM
By:DN platform editor
Recently, web hosting giant GoDaddy was ordered by the US Federal Trade Commission (FTC) to rectify security vulnerabilities and strengthen security measures.

Recently, web hosting giant GoDaddy was ordered by the US Federal Trade Commission (FTC) to rectify security vulnerabilities and strengthen security measures.

The FTC pointed out that since 2018, GoDaddy has failed to implement reasonable and appropriate security measures to protect and monitor its website hosting environment. The company has many problems, such as not properly managing assets and software updates, not assessing the risks of shared hosting services, not adequately recording and monitoring security-related events, and not isolating shared hosting from unsafe environments.

GoDaddy was ordered to strengthen security measures

Its loose patch system is implemented by each product team independently and lacks centralized management, resulting in serious vulnerabilities in a large number of boxes in the shared hosting environment, allowing hackers to steal user credentials and credit card information within months.

In addition, its customized Internet-facing API has security risks, is open to the Internet and unprotected, uses plaintext credentials and has no multi-factor authentication, which also gives hackers an opportunity to take advantage. Between 2019 and 2022, these security flaws caused multiple security vulnerabilities, and hackers gained unauthorized access to customer websites and data.

Although GoDaddy claims on its website, social media and emails that it has deployed reasonable security measures and complies with the relevant Privacy Shield framework, the FTC believes this is misleading.

However, in the settlement agreement, GoDaddy neither admitted nor denied wrongdoing, and no fines were attached. But it agreed to establish a comprehensive information security program, including creating a centralized inventory and management system for hardware, software and firmware, using automated tools to analyze events in real time and retain system audit logs, and launching multi-factor authentication methods for employees. It is also necessary to hire an independent third party to review its security plan every two years and no longer make false statements about security measures.

The FTC emphasized that many companies rely on web hosts like GoDaddy to ensure the security of their websites, and this action is intended to encourage them to strengthen their security systems and protect consumers around the world. GoDaddy said it has implemented some of the requirements and plans to continue investing in defensive measures to ensure the security of customers, websites and data.

Information source: domainincite

Contact Us
contact@dn.com
+86 135-7488-8887
3814848
Please scan the code using WeChat