If they had self-hosted their own repos, they might have had more luck.
Even regarding the blast radius, I do not really believe any company is honest about it. They do not have tools to verify it, if the user information was accessed with leaked token or real token. The thing that works in their favor is that no one else can verify it either which absolves them from any responsibility. Any platform engineer knows that your CICD system has the keys to the kingdom.
> The thing that works in their favor is that no one else can verify it either which absolves them from any responsibility
That's not how this works, at all. You need to have enough evidence that you can confidently demonstrate that there is no sign of a broader breach. If you get sued and can't do that, you're in trouble, because being unable to do that shows that you were acting negligently.
Also, the idea that this type of thing could just be stood up as a "not-for-profit" company and ran for peanuts is kind of silly. How would the nominal fee pay for the engineers and infrastructure? Or would this just be a volunteer effort and you'd like people to do this for free for you?
From what I have seen a large chunk of internet exists and stands on the shoulder of folks who did the volunteer work cause they were passionate about it and enjoyed that part. Once built, the nominal fee for API to check IP address should cover the costs way easily for the servers.
Letsencrypt is a great example, it did took away the big money from all these commercial CA's, who used to issue blue, green and what not kind of checkmarks. Thats one big reason reason why the migration to HTTPS happened faster.
It's quite a bit less expensive than most other commercial products of this kind that I've looked at.
> Any company where understanding of security practices has a direct impact on its revenue from early phases can be considered as a security company in my view.
This could, quite literally, be any company on earth then? But not CrowdSec, because they had a single security issue? Every company on earth has had those, including every security company.
My observation is generic and more about state of things rather than focusing on one entity.
Also lets not belittle the hard work by just labelling it out as free. If only money had been motivation for everyone then the world would have been a different place. And like a lot of people I have done my share of passionate work that provided satisfaction to me and money for others, thats way tangential though
You are the one who stated a specific company wasn't a security company. When asked to define what one was, your definition included any company on the planet.
> Also lets not belittle the hard work by just labelling it out as free
Who is belittling it? My point is that it's hard work and should be rewarded, not expected by someone to be done for them.
fallacy is "Oh I guess you mean" .. insert large unsolvable and probably unpopular derailment. Bonus points for aggressive labeling of the opponent being opposed to money.
apologist - "Any company on earth" .. We all stand together, Every Company On Earth .. does this warrent serious replies?
> aggressive labeling of the opponent being opposed to money
What? Where, exactly, did I do that? I stated they were opposed to _spending money_ on a service that they would find useful.
> Any company on earth
Their definition of a "security company" would include almost any type of company on earth, as long as they took security seriously. I asked them for a definition of a security company, since they claimed that CrowdSec wasn't one, and their definition had no boundaries.
Improve your reading comprehension and maybe study some actual logic, not whatever reddit nonsense you've got going here. But other than that, A+ work dude. I'm sure you were really impressed with what you wrote. "Shall we dig in?" ... ffs.