Our security auditor is an idiot. How do I give him the information he wants?
1–10 of 50 posts
Re: Our security auditor is an idiot. How do I give him the information he wants?
#2Re: Our security auditor is an idiot. How do I give him the information he wants?
#3Definitely seems less like a auditor (I believe asking for some of that is flat out illegal) and more like a hacker posing as a auditor, trying to get passwords/creditcard #'s.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#4Re: Our security auditor is an idiot. How do I give him the information he wants?
#5Perhaps the auditor is smarter than everyone thinks and is expecting the sysadmin to come to him empty handed and with an explanation as to why the requirements aren't reasonable.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#6Perhaps the auditor is smarter than everyone thinks and is expecting the sysadmin to come to him empty handed and with an explanation as to why the requirements aren't reasonable.
The "social engineering" idea is definitely worth considering, and the poster definitely needs to run this up the flag pole to his senior management. Preferably, this email would also have the words "contact our legal counsel" prominently displayed.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#7Definitely seems less like a auditor (I believe asking for some of that is flat out illegal) and more like a hacker posing as a auditor, trying to get passwords/creditcard #'s.
Bang on. Most likely social engineering. If this were actually an employee, they should be fired/told to fuck off.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#8He did manage to start a very popular thread, and get a ton of people with really high rep to respond AND get a link on HN. He just threw out some bait, and the community swarmed like starving fish.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#9Earlier quoted context omitted.
Bang on. Most likely social engineering. If this were actually an employee, they should be fired/told to fuck off.
A social engineer wouldn't try for this much data. One SSH key or password would be enough. I'm going with the fucking-retarded-auditor theory.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#10Earlier quoted context omitted.
A social engineer wouldn't try for this much data. One SSH key or password would be enough. I'm going with the fucking-retarded-auditor theory.
Then again, it could be a social engineer trying to play off the commonly-held belief that an actual social engineer wouldn't ask for something so blatantly illegal.