Our security auditor is an idiot. How do I give him the information he wants?
31–40 of 50 posts
Re: Our security auditor is an idiot. How do I give him the information he wants?
#32Earlier quoted context omitted.
You think too much. Usually, the simplest explanation is also the correct one. I put my money on retarded auditor who thinks he's more clever and powerful than he is.
It never hurts to be careful. When it comes to security, defense requires closing all possible holes, while offense requires finding only one. It would be irresponsible for the employee not to at least be cautious when dealing with this auditor. It's worth taking a few minutes to call the company performing the audits and verify that the auditor is who he says he is.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#33Everyone so far has focused on the auditor, but I want to know why the OP thinks faking the requested data is an acceptable response. That disturbs me and nobody else commented on it!
Re: Our security auditor is an idiot. How do I give him the information he wants?
#34Earlier quoted context omitted.
It never hurts to be careful. When it comes to security, defense requires closing all possible holes, while offense requires finding only one. It would be irresponsible for the employee not to at least be cautious when dealing with this auditor. It's worth taking a few minutes to call the company performing the audits and verify that the auditor is who he says he is.
IMO, that should actually be part of the process of passing a security audit. Which suggests someone who is doing an audit will ask for information that if given to him will cause you to fail the audit.
In fact, this seems like a more effective way to sniff out plaintext password storage than saying "show me everywhere you touch passwords and how they're encrypted".
Re: Our security auditor is an idiot. How do I give him the information he wants?
#35Please post the name of the company that the security auditor works for.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#36I flagged this. The likely explanation is that this is just a troll -- 2-day-old account, this is the only question that's been asked on it. There's no way that somebody that's been doing audits for 10 years would ask for this stuff, and there's no way any server admin would even consider providing the information. ...At least, any server admin that shouldn't be yoinked back down to making patch cables.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#37Earlier quoted context omitted.
IMO, that should actually be part of the process of passing a security audit. Which suggests someone who is doing an audit will ask for information that if given to him will cause you to fail the audit.
Confirming that he is an auditor is insufficient. A sufficiently clever legitimate auditor might attempt social engineering attacks and fail you if they succeed. In fact, this seems like a more effective way to sniff out plaintext password storage than saying "show me everywhere you touch passwords and how they're encrypted".
One of the more interesting government audits I have heard about was the auditor did a basic internal audit and said he was part of physical secuity ect so people knew he was part of the audit team. He then showed up late, turning off the power supply to the building and then pointing at people who show up at the generator and saying "bang your dead" this is part of an audit etc. If they failed to call security before everyone was "dead" they where considered to have failed that part of the audit. He also attempted to get into the building without showing up on camera's ect. All of which sounds like a fun job and a good idea.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#38This is suspicious: *The "new security policies" were introduced two weeks before our audit, and the six months historical logging was not required before the policy changes. These "policies" were introduced by whom? His payment processor or by his company on the advice of this "auditor"? Or did the OP make this up? In short, I need; A way to 'fake' six months worth of password changes and make it look valid A way to…
Yes, I wondered the same thing! Aside from the legal implications, the OP seems to have some questionable ethics as well.
Of course, quitting is the other out, but I do think he has a moral obligation to prevent his company from handing any of this information over to the auditor.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#39Earlier quoted context omitted.
Bang on. Most likely social engineering. If this were actually an employee, they should be fired/told to fuck off.
A social engineer wouldn't try for this much data. One SSH key or password would be enough. I'm going with the fucking-retarded-auditor theory.
Asking for everything might sound more legitimate than asking for one small thing. Perps generally go with their gut. In this case, this "auditor" shot for the moon with the wrong mark.
Re: Our security auditor is an idiot. How do I give him the information he wants?
#40Please post the name of the company that the security auditor works for.