TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How do I give our security auditor the information he wants? (2011)

204 pointsby gadtflyover 8 years ago

14 comments

madaxe_againover 8 years ago
Birmingham? I think I know this guy - we have a client based there and are three years into a war with their PCI auditor, who are dangerously incompetent. They were adamant that we should be able to decrypt PANs (credit card numbers) - we still haven&#x27;t complied, as we quite deliberately don&#x27;t store them and just transit them.<p>It&#x27;s not a phishing scam, this is pretty much state of the art in the UK - and try being a 32 year old &quot;kid&quot; company director while the 55 year old &quot;security engineer&quot; who seems to have never used a computer and thinks a network is a maritime term plays the &quot;seniority&quot; card in front of a client of the same generation.<p>The sad thing is I&#x27;ve seen two retailers drive themselves hard into the ground over the last eighteen months by listening to this variety of chumbly wotsit rather then someone who actually knows what the hell they&#x27;re talking about.<p>One spent about £8M on their PCI auditor over six months, then went bust, blaming us, the platform provider - who are PA-DSS and ISO certified. The auditor blamed us too, then folded up shop and moved to Spain.<p>PCI experts are the new SEO experts.
评论 #12435413 未加载
评论 #12434455 未加载
评论 #12434914 未加载
评论 #12434432 未加载
评论 #12434654 未加载
评论 #12436501 未加载
评论 #12434683 未加载
评论 #12435523 未加载
jonsgover 8 years ago
Well, if the auditor wants to play willy-measuring tactics: I&#x27;ve been using Unix since 1982 (Bell Labs Version 7, since you asked), and I rather suspect that I&#x27;ve more experience than he has.<p>UNIX and derived&#x2F;lookalike systems like Linux have _always_ stored passwords one-way encrypted. I have precisely no idea how he expects the sysadmin to provide a list of plaintext passwords, short of replacing the passwd utility with a hacked one that stores the pre-crypt version somewhere for retrieval, or asking staff to email their plaintext passwords to the poor sap he&#x27;s badgering.<p>Either way, a massive security breach. The whole point of one-way encryption is that there is no persistent trace left of the original plaintext password. This guy&#x27;s way of auditing security recalls the Spanish Inquisition&#x27;s way of auditing witchcraft. Damned if you do; damned if you don&#x27;t.<p>His company&#x27;s far better off using a payments provider with a clue - and a competent auditor.
评论 #12436495 未加载
评论 #12436496 未加载
rajadigopulaover 8 years ago
&quot;I&#x27;m going to assume you do not have PCI installed on your servers as being able to recover this information is a basic requirement of the software.&quot;<p>I already fell off my chair.
评论 #12435033 未加载
sfifsover 8 years ago
Hmmm... perhaps the auditor should be informed that if he persists in requesting for user account and passwords in the guise of a security audit, you will have no choice but to report him to the FBI or MI5 as a suspected phishing scam operator who may have already compromised prior clients in similarly.
评论 #12437917 未加载
0xbadcafebeeover 8 years ago
Does nobody find it unprofessional, perhaps even untrustworthy, to not only discuss the private dealings you have with other companies but also copy+paste e-mails? Even if they&#x27;re idiots? I don&#x27;t think you want to go down that road... <i>&quot;Well I thought the guy from Company X was an idiot, so why was it wrong for me to repost our private conversation?&quot;</i>
评论 #12434441 未加载
评论 #12434745 未加载
评论 #12434448 未加载
评论 #12436962 未加载
评论 #12434659 未加载
gtf21over 8 years ago
This looks more like a phishing scam than a security audit. Anyone asking for things like plain-text passwords sounds a bit fishy to me.
评论 #12440936 未加载
lamontcgover 8 years ago
Its likely this isn&#x27;t a troll post.<p>The security community has a whole lot of idiots in it who figured out that they can get a CISSP and turn themselves into a security auditor and get paid extremely well while getting to enjoy acting like tyrants. In reality they&#x27;re not fit to manage a McDonalds.
aaron695over 8 years ago
2011 and still as fake, HN version of the outrage train.<p>At least it&#x27;s a little nerdy :)
jonsgover 8 years ago
Worth mentioning, BTW, that the original article is five years old. It&#x27;s ready to go to primary school.
beachstartupover 8 years ago
this is either a fictional troll, or a phishing scam. come on.
0xmohitover 8 years ago
It seems that the auditor wanted a fancier designation and decided upon &quot;security auditor&quot;.<p>It is also possible that the auditor in question worked in a (physical) security agency in past life and failed to understand that computer security is not quite the same.<p>That seems to be the only plausible explanation for demanding actual plain-text passwords (past&#x2F;present&#x2F;whatever) and so on.
评论 #12434524 未加载
nicky0over 8 years ago
Makes me so mad, I have to to think this is some kind of joke or wind-up. Hopefully it is...
tillinghastover 8 years ago
A brilliant troll &#x2F; piece of entertainment. The author basically reveals it here in Update #3:<p>&gt; Our software has now moved onto PayPal so we know it&#x27;s safe.
评论 #12436874 未加载
rngesusover 8 years ago
Dangerous, especially the request(s) for plain-text passwords.