Am I the only one who thinks the story is a little too perfect and ridiculous? It is much more likely that the author simply fabricated the story. He did manage to start a very popular thread, and get a ton of people with really high rep to respond AND get a link on HN. He just threw out some bait, and the community swarmed like starving fish.
And what would be the benefit?
Our security auditor is an idiot. How do I give him the information he wants?
21–30 of 50 posts
Re: Our security auditor is an idiot. How do I give him the information he wants?
#22Earlier quoted context omitted.
It's a throwaway account. It has "throwaway" in its name. The question ends with the asker explaining that he's posting it from a throwaway account because he doesn't want his real name associated with it. How many questions would you expect a throwaway account to have?
I know what throwaway accounts are, and I read his username. It's still a troll.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#23Re: Our security auditor is an idiot. How do I give him the information he wants?
#24Earlier quoted context omitted.
I know what throwaway accounts are, and I read his username. It's still a troll.
If there's a kind of person on the internet that I dislike more than trolls, it is people who see trolls in everyone.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#25Definitely seems less like a auditor (I believe asking for some of that is flat out illegal) and more like a hacker posing as a auditor, trying to get passwords/creditcard #'s.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#26Re: Our security auditor is an idiot. How do I give him the information he wants?
#27 *The "new security policies" were introduced two weeks
before our audit, and the six months historical logging
was not required before the policy changes.
These "policies" were introduced by whom? His payment processor or by his company on the advice of this "auditor"?
Or did the OP make this up? In short, I need;
A way to 'fake' six months worth of password changes
and make it look valid
A way to 'fake' six months of inbound file transfers
Why is the poster requesting help generating plausible fake data? Is he naive? Afraid of losing his job? Unaware of the legal implications?Re: Our security auditor is an idiot. How do I give him the information he wants?
#28Re: Our security auditor is an idiot. How do I give him the information he wants?
#29This is suspicious: *The "new security policies" were introduced two weeks before our audit, and the six months historical logging was not required before the policy changes. These "policies" were introduced by whom? His payment processor or by his company on the advice of this "auditor"? Or did the OP make this up? In short, I need; A way to 'fake' six months worth of password changes and make it look valid A way to…
Re: Our security auditor is an idiot. How do I give him the information he wants?
#30Everyone so far has focused on the auditor, but I want to know why the OP thinks faking the requested data is an acceptable response. That disturbs me and nobody else commented on it!