While I like the visibility w/ the #kolektiva breach I also think this is missing the forest for the trees and gets distracted while skipping a lot of the practices that would have actually helped, and things like "VPN!" are just eyeroll worthy
For example.
1. Don't download your users database onto a personal device.
2. If you violate (1), don't ever have it unencrypted.
3. If you violate (1) and (2) don't go "well maybe we can just not tell anyone for six weeks."