The Federal Trade Commission (FTC) will require web hosting giant GoDaddy to implement basic security protections, including HTTPS APIs and mandatory multi-factor authentication, to settle charges that it failed to secure its hosting services against attacks since 2018. FTC says the Arizona-based company's claims of reasonable security practices also misled millions of web-hosting customers because GoDaddy was instead "blind to vulnerabilities and threats in its hosting environment" due to its failings to implement standard security tools and practices. "Millions of companies, particularly small businesses, rely on web hosting providers like GoDaddy to secure the websites that they and their customers rely on," said Samuel Levine, Director of the FTC's Bureau of Consumer Protection. "The FTC is acting today to ensure that companies like GoDaddy bolster their security systems to protect consumers around the globe." According to the FTC's complaint, GoDaddy's unreasonable security practices included failing to use multi-factor authentication (MFA), manage software updates, log security-related events, segment its network, monitor for security threats (including by failing to use software that could actively detect threats from its many logs), and use file integrity monitoring. The company also failed to inventory and manage assets, assess risks to its website hosting services, and secure connections to services that provide access to consumer data. The FTC says that, between 2...
FTC orders GoDaddy to fix poor web hosting security practices
BleepingComputer
·Sergiu Gatlan
·Published Jan 16, 2025
·Updated
Affected Software
3 affected components
GoDaddy Managed WordPress
GoDaddy cPanel shared hosting
GoDaddy web hosting
Frequently Asked Questions
1
What security measures has the FTC ordered GoDaddy to implement?
The FTC has ordered GoDaddy to implement HTTPS APIs and mandatory multi-factor authentication.
2
What prompted the FTC's intervention with GoDaddy?
The FTC intervened due to charges that GoDaddy failed to secure its web hosting services adequately.
3
Which GoDaddy products are affected by the FTC's order?
The affected GoDaddy products include Managed WordPress, cPanel shared hosting, and general web hosting services.
4
What are the potential risks of inadequate web hosting security?
Inadequate web hosting security can lead to data breaches, unauthorized access, and service disruptions.
5
What is the significance of this FTC ruling for web hosting services?
This ruling emphasizes the importance of basic security protocols in protecting user data for web hosting providers.