Live data from Hacker News

Our security auditor is an idiot. How do I give him the information he wants?

serverfault.com

11–20 of 50 posts

Re: Our security auditor is an idiot. How do I give him the information he wants?

#11
post #8

Am I the only one who thinks the story is a little too perfect and ridiculous? It is much more likely that the author simply fabricated the story. He did manage to start a very popular thread, and get a ton of people with really high rep to respond AND get a link on HN. He just threw out some bait, and the community swarmed like starving fish.

And he gains what, exactly, from doing this? Posting anonymously, he doesn't get any credit from posting the story.

Re: Our security auditor is an idiot. How do I give him the information he wants?

#12
post #8

Am I the only one who thinks the story is a little too perfect and ridiculous? It is much more likely that the author simply fabricated the story. He did manage to start a very popular thread, and get a ton of people with really high rep to respond AND get a link on HN. He just threw out some bait, and the community swarmed like starving fish.

And what would be the benefit?

Re: Our security auditor is an idiot. How do I give him the information he wants?

#13
post #10

Earlier quoted context omitted.

Then again, it could be a social engineer trying to play off the commonly-held belief that an actual social engineer wouldn't ask for something so blatantly illegal.

You think too much. Usually, the simplest explanation is also the correct one. I put my money on retarded auditor who thinks he's more clever and powerful than he is.

It never hurts to be careful. When it comes to security, defense requires closing all possible holes, while offense requires finding only one. It would be irresponsible for the employee not to at least be cautious when dealing with this auditor. It's worth taking a few minutes to call the company performing the audits and verify that the auditor is who he says he is.

Re: Our security auditor is an idiot. How do I give him the information he wants?

#14
post #11
post #8

Am I the only one who thinks the story is a little too perfect and ridiculous? It is much more likely that the author simply fabricated the story. He did manage to start a very popular thread, and get a ton of people with really high rep to respond AND get a link on HN. He just threw out some bait, and the community swarmed like starving fish.

And he gains what, exactly, from doing this? Posting anonymously, he doesn't get any credit from posting the story.

It's called trolling. It's been done since there were bangs in people's email addresses.

The modern currency for trolls is "lulz".

Re: Our security auditor is an idiot. How do I give him the information he wants?

#15
I flagged this. The likely explanation is that this is just a troll -- 2-day-old account, this is the only question that's been asked on it. There's no way that somebody that's been doing audits for 10 years would ask for this stuff, and there's no way any server admin would even consider providing the information. ...At least, any server admin that shouldn't be yoinked back down to making patch cables.

Re: Our security auditor is an idiot. How do I give him the information he wants?

#16
post #2

Definitely seems less like a auditor (I believe asking for some of that is flat out illegal) and more like a hacker posing as a auditor, trying to get passwords/creditcard #'s.

Who in their right mind would give their SSH private key to anyone?

It's a private key after all.

Re: Our security auditor is an idiot. How do I give him the information he wants?

#17

I flagged this. The likely explanation is that this is just a troll -- 2-day-old account, this is the only question that's been asked on it. There's no way that somebody that's been doing audits for 10 years would ask for this stuff, and there's no way any server admin would even consider providing the information. ...At least, any server admin that shouldn't be yoinked back down to making patch cables.

It's a throwaway account. It has "throwaway" in its name. The question ends with the asker explaining that he's posting it from a throwaway account because he doesn't want his real name associated with it. How many questions would you expect a throwaway account to have?

Re: Our security auditor is an idiot. How do I give him the information he wants?

#18

I flagged this. The likely explanation is that this is just a troll -- 2-day-old account, this is the only question that's been asked on it. There's no way that somebody that's been doing audits for 10 years would ask for this stuff, and there's no way any server admin would even consider providing the information. ...At least, any server admin that shouldn't be yoinked back down to making patch cables.

Regarding the age of the account, there is a note at the end of the post: "Sidenote; I'm posting from a throw-away account to (mostly) dis-associate my name from this post"

Re: Our security auditor is an idiot. How do I give him the information he wants?

#19

I flagged this. The likely explanation is that this is just a troll -- 2-day-old account, this is the only question that's been asked on it. There's no way that somebody that's been doing audits for 10 years would ask for this stuff, and there's no way any server admin would even consider providing the information. ...At least, any server admin that shouldn't be yoinked back down to making patch cables.

It's a throwaway account. It has "throwaway" in its name. The question ends with the asker explaining that he's posting it from a throwaway account because he doesn't want his real name associated with it. How many questions would you expect a throwaway account to have?

I know what throwaway accounts are, and I read his username.

It's still a troll.

Re: Our security auditor is an idiot. How do I give him the information he wants?

#20
This is a case of social engineering, not of a security auditor, but of the poster. The poster wants to know an easy way to collect public and private SSH keys and fake 6 months of inbound traffic. There is no auditor.

Maybe the poster is writing a book on cracking systems? Who knows. But it smells like a hoax.

Post reply on HN