TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Our security auditor is an idiot. How do I give him the information he wants?

70 点作者 ashwin_kumar大约 11 年前

9 条评论

rdl大约 11 年前
The last time this got discussed, I thought the consensus was he was trolling -- the point being the correct answer is to explain why you don&#x27;t have these (technical controls, hashing of passwords, etc.).<p>The other reason would have been if he wanted login access to servers to validate configs himself, but there are much better ways to accomplish that (I&#x27;d be very reluctant to give an auditor anything but read-only access to any production infrastructure, but it is valid to want to know that what is being given to you matches production; there are ways to accomplish both).
评论 #7456232 未加载
Zenst大约 11 年前
WOW, &quot;A security auditor for our servers has demanded the following within two weeks: •A list of current usernames and plain-text passwords for all user accounts on all servers •A list of all password changes for the past six months, again in plain-text&quot;<p>That right there would be a security breach&#x2F;issue and for it to be created as part of an audit is unbelievable.<p>I have never met any security auditor who has done that or ever would and having done audits myself for FTSE 100 companies, well if I did that I&#x27;d be out of a job. Certainly audit the passwords, though there should be rules to prevent silly passwords and that is what should be audited.<p>In such a situation I would not panda to such a auditor and would approach a director about the security risk the auditor was and good night veanna for them. Such people should not be doing audits, ever and clearly not qualified in the role&#x2F;task they have been given.<p>It would be a security issue too carry on supporting or allowing such a person to carry on auditing as they are clearly a security risk without a doubt.
评论 #7457299 未加载
评论 #7461253 未加载
avaku大约 11 年前
This is a trick. The correct thing to say to them - we don&#x27;t have passwords because they are hashed and salted. Then you successfully pass the security audit :)
DigitalSea大约 11 年前
This cannot be real, but sadly it appears as though it is. A &quot;professional&quot; security auditor request plain text passwords? A security auditor that thinks PCI is something you install onto your server? Wow. I am literally speechless.<p>Can we please get the name of this company somehow? This company should not be allowed to give anyone security advice whatsoever, they quite clearly do not know what they are talking about. I&#x27;d hate to think how many businesses have been affected and or are vulnerable as a result of their auditing practices and guidelines.
评论 #7456341 未加载
ChuckMcM大约 11 年前
I read that and it read like a troll, or that the &#x27;auditor&#x27; was socially engineering the firm (also possible). It is useful to have passwords explicitly unknown by anyone except their owners and run password cracking software on the password database continuously to weed out &#x27;weak&#x27; passwords.
mkonecny大约 11 年前
My heart sank as I read that. There are too many people in our field that don&#x27;t have a basic grasp on the most fundamental concepts, and yet are in the position to direct those that have a clue.
评论 #7456198 未加载
ppierald大约 11 年前
I hope this is a troll and if it is not, you should read through your contract, look for a breach clause, and exercise that clause. Otherwise, you should eat the cost of getting a new security auditor. A good relationship with a qualified auditor can be really beneficial to your organization. If you don&#x27;t have that, you are not getting any value out of the dollars spent.
aaron695大约 11 年前
This is either made up or the auditor has a mental health issue.<p>Either way nothing to see here unless you want to discuss mental health issues or truthfulness on the Internet and how to improve it.
评论 #7483419 未加载
autodidakto大约 11 年前
An idiot... like a fox. He was up to something, using bullying tactics to social engineer.