TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Dell announces security breach

66 点作者 frdmn超过 6 年前

5 条评论

donaltroddyn超过 6 年前
If software development was a true profession, then I firmly believe that many developers would be struck off for extreme negligence or incompetence.<p>I’ve found and reported serious security vulnerabilities to many companies that I’ve worked with, and become very disillusioned with some of the responses. Companies that operate in fields which materially affect people&#x27;s lives (such as healthcare, finance and telecoms) will deploy software that is so badly designed that there is often no need to break any technical aspect to get access to private and sensitive data.<p>Yet, when I report a breach, the same people who deployed software with broken (or sometimes no) authorisation models, access control, etc, are suddenly competent enough to investigate their own failure. Invariably, they always have perfect logging and reporting that could not possibly have been evaded and which proves that no breach occurred or data was exfiltrated before the vulnerability was reported.<p>If another professional, say an engineer, lawyer, or doctor, had demonstrated the incompetence or negligence in their field that I’ve seen some software developers display (sometimes wilfully - “It’s a feature”), they would never be allowed to work again. Software is now so important that I believe that some of the developers and technical leaders that I have dealt with in resolving security vulnerabilities should never again be allowed to work with software that interacts with personal or sensitive data (or, more generally, with software that could affect human life, safety, or privacy).
评论 #18560042 未加载
评论 #18560266 未加载
评论 #18560040 未加载
评论 #18560877 未加载
评论 #18560849 未加载
评论 #18565570 未加载
Already__Taken超过 6 年前
Dell&#x27;s been an open book for years.<p>One piece of spam I&#x27;ve got on a brand new email account was ~1 day after ordering a brand new XPS. It was a fake tracking code email about my dell order with correct details like laptop, account name, price. I contacted dell and only managed to find out my order wasn&#x27;t even in the post yet. They weren&#x27;t interested in anything.<p>And I also never got any more than that specific 1 piece of spam.
评论 #18560634 未加载
评论 #18561861 未加载
评论 #18559761 未加载
abo2t超过 6 年前
It&#x27;s insane that companies are allowed to say &quot;yes there was a security hole, but no we don&#x27;t have logs, therefore nothing was stolen, so stop asking.&quot;<p>Their refusal to give the number of exposed accoundlts makes it seem like it&#x27;s pretty bad.
tyingq超过 6 年前
Dell redirected the vulnerability press release link to a Christmas Deals page. Heh.
评论 #18560641 未加载
ndrake超过 6 年前
From <a href="https:&#x2F;&#x2F;www.dell.com&#x2F;customerupdate" rel="nofollow">https:&#x2F;&#x2F;www.dell.com&#x2F;customerupdate</a><p>What is a “hashed password”? Hashing is a cryptographic security mechanism, similar to encryption, that scrambles customers’ passwords into an unreadable format. Dell ‘hashes’ all Dell.com customer account passwords prior to storing them in our database using a hashing algorithm that has been tested and validated by an expert third-party firm. This security measure limits the risk of customers’ passwords being revealed if a hashed version of their password were to ever be taken.
评论 #18559782 未加载
评论 #18559781 未加载