Patreon Lays Off Its Entire Security Team

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
Article
Archive

Patreon Lays Off Its Entire Security Team​


That could be a problem for a platform that manages payments, contact information, and more.​

Patreon has reportedly laid off its entire security team.

CyberScoop reports that several former employees have confirmed the layoffs, which occurred last week, and that Patreon doesn't seem to be worried about no longer having a security team.



"As part of a strategic shift of a portion of our security program, we have parted ways with five employees," Patreon told CyberScoop. "The changes made this week will have no impact on our ability to continue providing a secure and safe platform for our creators and patrons."


NBC News reporter Kevin Collier says that Patreon said in a statement that it "partner with a number of external organizations to continuously develop our security capabilities and conduct regular security assessments to ensure we meet or exceed the highest industry standards."

Many companies operate without dedicated security teams. Some have their IT department handle security for them, others turn to managed security service providers (MSSPs), and still others rely on some combination of crossed fingers, rabbit feet, and optimism.

But those companies aren't typically as large as Patreon. The company says on its website that more than 250,000 creators are using its platform to deliver content to over 8 million patrons. Those creators are said to have earned more than $3.5 billion—and that's after Patreon's fees.

Patreon is also entrusted with a lot of information about creators and patrons alike. That includes payment details, contact information, and in some cases shipping addresses used to deliver physical rewards to backers, not to mention patron-exclusive content hosted on the platform.

In a message to Patreon's Discord server shared with PCMag, Patreon's Senior VP of Engineering Utkarsh Srivastava said the company isn't "scaling back investing in our security programs" and would actually be "expanding our investment in security as we continue to grow."

There seems to be a disconnect between Patreon letting its entire security team go, as now-former senior security engineer Emily Metcalfe said on LinkedIn, and Srivastava telling creators the company is looking to invest more in the security of its platform moving forward.

Srivastava said that "there has been no security breach or incident of any kind in recent months" and that "this action was not the result of a breach or incident, external or internal." So it's not clear how an expanded investment in security is related to laying off security professionals.

In a statement, a Patreon spokesperson told us "more investments mean outside partnerships, engineering expertise we've added in recent months to our infrastructure and payments teams, and the fact that we are hiring heavily in engineering and product development right now."
 
This can only end so well...

Oh fuck it, never correct your enemy when he is doing a mistake
 

the author of this article posted in on hackernews and was talking in the comments section. nothing really concrete, just thought I'd post it
This article is really interesting, showing sources about these allegations going as far back as 2017. I'm trying to remember, when did Patreon start removing creator pages who draw anime characters, including those 18+ creators who strictly draw adult anime characters? The article mentions complaints that there are creators making animated child rape .gifs, with one saying the animation was looking more and more hyper-realistic. Sounds like they were cherry-picking what was to be removed to placate someone while ignoring the actual real problem.
 
Back