
At the same time, if they want to come back and view the findings regularly, or receive weekly or monthly notifications, they can purchase a subscription starting at $9 per month. This is in no way required, but it's available.
Why?
Early last year, in an attempt to notify, we sent over 200,000 notifications to the abuse email addresses listed in domain registrations. We used a text-based format similar to that used by Carnegie Mellon/CERT-CC back in the early days of victim notification. We received mixed feedback. Some were appreciative of the notification, others, well, not so much. Today however, many use registration privacy proxies. So… we sent what we thought was a polite email, with that explainer video, short instructions, and a link. We tried this for about a month, retiring the email as part of A | B testing with a new format currently in the works.
We struggled with the idea of email. As security folks, we teach people not to click. We've tried direct personalized notifications, we've talked with scores of folks that we thought might be of assistance in getting the word out; yet, the problem grows exponentially.
We've seen a few clean-ups as a result of the notifications —even without having them come to our site, but the others? They continue to be exploited.
So here's the question? If we know about all of these victims, many with exposed passwords, others hitting sinkholes, most having no idea what to do about it, why not let them know? If their social security numbers are lost, and their privacy information were on the web, are they notified? Yes.
Is email the best way? No. We knew that going in. This is a hard question. We're not sure what the right answer is. We're not a big company. We share information and we try our best to always do the right thing, but in this case, there are SO many victims.
We're open to suggestions. How do we get the word out without looking like spammers? If there are others with thoughts on how this might be accomplished, We'd love to hear it.
For those of you who've received the notifications and thought it was spam? We apologize. That however, does not make the notification any less real. We might have done it better (and we will in the future) but we would urge you to take it seriously.