TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: How to address security incident without offending coworker?

2 pointsby BaronVonSteubenover 6 years ago
Recently at work I had a friend use an insecure medium to send me a password to a production account. This is a big security faux paus, and means we need to rotate that password ASAP and consider the old one compromised. But this question has nothing to do with the technical side.<p>The friend that sent me the password was trying to be helpful, and truly I appreciated his help. If I blow the metaphorical security whistle in his face regarding this security issue, it will probably hurt his feelings and may provide a disincentive to be helpful in the future. However, I obviously want to prevent disclosures like this in the future.<p>How would you handle this situation?

2 comments

ergothusover 6 years ago
Ask them to lead the clean up it themselves. This let&#x27;s you acknowledge their good intentions and doesn&#x27;t feel like you are throwing them under the bus behind their back (bad analogy).<p>They screwed up, but this lets them look responsible and self accountable. There is no cure for bad management, but with decent management the friend will be more embarrassed than anyone would be judgemental - screwups happen, coverups or ignoring them is the thing that is far worse.
KineticTroiover 6 years ago
If it&#x27;s really that important to be secure, I&#x27;d use an electronic password generator fob that intermixed the password list with a universal cosmic radio background radiation signal.<p>Perhaps he just gave you a one time use password. Or maybe not. I just know, if you want the password delivered in person, only ask for it, in person.<p>I&#x27;d probably rethink the whole system, and not the user.