惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
大猫的无限游戏
大猫的无限游戏
Vercel News
Vercel News
V
Visual Studio Blog
Microsoft Azure Blog
Microsoft Azure Blog
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
罗磊的独立博客
N
Netflix TechBlog - Medium
M
MIT News - Artificial intelligence
G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
P
Proofpoint News Feed
小众软件
小众软件
Engineering at Meta
Engineering at Meta
D
DataBreaches.Net
S
SegmentFault 最新的问题
H
Help Net Security
量子位

Troy Hunt's Blog

Weekly Update 521: Breach Perception v. Reality Weekly Update 520: The Unscripted Edition Weekly Update 519: Breaches & Data Integrity A Cautionary Tale About Data Breach Claims, Verification and Carhartt Weekly Update 518: IoT Doorlock Nirvana with UniFi Welcoming the Sri Lankan Government to Have I Been Pwned Weekly Update 517: Cyber Ransoms Weekly Update 516: Live From Vietnam Welcoming the Nepalese Government to Have I Been Pwned Weekly Update 515 Weekly Update 514: This Week in Data Breaches Weekly Update 513: Clauding The Home Network Weekly Update 512: IoT Lockout Fail Weekly Update 511: Live from my Riad in Marrakech Swimming Pools, Pee, and Trying to Delete Your Data From the Internet Weekly Update 510: Live From Mallorca with Scott Helme Weekly Update 509 Weekly Update 508 Weekly Update 507 Welcoming the Philippine Government to Have I Been Pwned 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever Weekly Update 506 Welcoming the Bhutanese Government to Have I Been Pwned Weekly Update 505 Welcoming the Bahamian Government to Have I Been Pwned Welcoming the Bangladesh Government to Have I Been Pwned Welcoming the Costa Rican Government to Have I Been Pwned Weekly Update 503 Weekly Update 502 Weekly Update 501
Weekly Update 504
Troy Hunt · 2026-05-18 · via Troy Hunt's Blog

It's a hot topic, the old "pay or don't pay" for hackers not to leak your data. Since recording this a few days ago, we've had Grafana go with the "no pay" approach, and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom". I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which really waters down the severity of the whole thing. It looks like, for the time being, "pay or leak" is the new norm... along with nonsensical statements like "the data was returned to us" 🤷‍♂️

Listen on Apple Podcasts

Watch and Listen on YouTube

Download via RSS

Weekly update