Live data from Hacker News

Our security auditor is an idiot. How do I give him the information he wants?

serverfault.com

41–50 of 50 posts

Re: Our security auditor is an idiot. How do I give him the information he wants?

#41
post #7
post #3

Earlier quoted context omitted.

Bang on. Most likely social engineering. If this were actually an employee, they should be fired/told to fuck off.

A social engineer wouldn't try for this much data. One SSH key or password would be enough. I'm going with the fucking-retarded-auditor theory.

[deleted]

Re: Our security auditor is an idiot. How do I give him the information he wants?

#42

I flagged this. The likely explanation is that this is just a troll -- 2-day-old account, this is the only question that's been asked on it. There's no way that somebody that's been doing audits for 10 years would ask for this stuff, and there's no way any server admin would even consider providing the information. ...At least, any server admin that shouldn't be yoinked back down to making patch cables.

It's a throwaway account. It has "throwaway" in its name. The question ends with the asker explaining that he's posting it from a throwaway account because he doesn't want his real name associated with it. How many questions would you expect a throwaway account to have?

Yea, I can understand why they asked this from a throwaway account. Ideally it should not be needed, but...

Re: Our security auditor is an idiot. How do I give him the information he wants?

#43
post #8

Am I the only one who thinks the story is a little too perfect and ridiculous? It is much more likely that the author simply fabricated the story. He did manage to start a very popular thread, and get a ton of people with really high rep to respond AND get a link on HN. He just threw out some bait, and the community swarmed like starving fish.

He just threw out some bait, and the community swarmed like starving fish.

This is true of all "light" SO/SF posts. Nobody gets excited about answering someone's obscure apt-get question. Everyone gets excited when they can spend their boring workday telling some dude that his security consultant is fucking him. It's the same reason people read "People Magazine" instead of "Purely Functional Data Structures".

Re: Our security auditor is an idiot. How do I give him the information he wants?

#44

This is a case of social engineering, not of a security auditor, but of the poster. The poster wants to know an easy way to collect public and private SSH keys and fake 6 months of inbound traffic. There is no auditor. Maybe the poster is writing a book on cracking systems? Who knows. But it smells like a hoax.

What is 'hard' about harvesting public and private keys? Especially if you are the sysadmin.

What purpose would faking 6 months of inbound traffic serve? If he just wanted to cover his tracks, wouldn't he just erase logs rather than trying to make them look legit? That would seem like doing things the hard way.

Re: Our security auditor is an idiot. How do I give him the information he wants?

#45

Earlier quoted context omitted.

Yes, I wondered the same thing! Aside from the legal implications, the OP seems to have some questionable ethics as well.

What's unethical about that? If politics have required him to do provide information he can't legally provide, falsifying the information seems like the only reasonable course of action. Of course, quitting is the other out, but I do think he has a moral obligation to prevent his company from handing any of this information over to the auditor.

The only ethical course of action is to stop the circus and explain to your manager:

- what this guy is asking for

- how that is in violation of the PCI data security standard

- explain that you are not able, and not allowed to provide this information

- explain that this likely means the auditor is a hack and steps need to be taken to get a proper auditor

Re: Our security auditor is an idiot. How do I give him the information he wants?

#46

I flagged this. The likely explanation is that this is just a troll -- 2-day-old account, this is the only question that's been asked on it. There's no way that somebody that's been doing audits for 10 years would ask for this stuff, and there's no way any server admin would even consider providing the information. ...At least, any server admin that shouldn't be yoinked back down to making patch cables.

Troll or not, it generated good responses and summaries of standard security.

Re: Our security auditor is an idiot. How do I give him the information he wants?

#48
post #45

Earlier quoted context omitted.

What's unethical about that? If politics have required him to do provide information he can't legally provide, falsifying the information seems like the only reasonable course of action. Of course, quitting is the other out, but I do think he has a moral obligation to prevent his company from handing any of this information over to the auditor.

The only ethical course of action is to stop the circus and explain to your manager: - what this guy is asking for - how that is in violation of the PCI data security standard - explain that you are not able, and not allowed to provide this information - explain that this likely means the auditor is a hack and steps need to be taken to get a proper auditor

I suspect either his manager knows, or he is in a position where he doesn't have a manager.

To quote: if I don't provide this information we loose access to our payments platform

Re: Our security auditor is an idiot. How do I give him the information he wants?

#49
post #47

I wonder if, when confronted about how ridiculous the requests were, the auditor will claim to have been testing how well the admins resisted social engineering?

I was in exactly that situation myself recently. However I was hungry and the auditor was cute and I told her I would give her the root password in exchange for a donut. Which she dutifully wrote down on her clipboard. Now the whole company has to go on training. I don't even know the root password!

Re: Our security auditor is an idiot. How do I give him the information he wants?

#50

Perhaps the auditor is smarter than everyone thinks and is expecting the sysadmin to come to him empty handed and with an explanation as to why the requirements aren't reasonable.

The poster has already tried that, which is when the "auditor" replied with the "10 years experience" rant. If this actually is his tactic, then he should be fired simply on the principle that his modus operandi will cost the company clients, as it seems to be in this case. If he just has his head up his ass, then he needs to be fired for gross incompetence and the company may need to notify anyone that he's previous…

Allegedly ten years of experience is more than anyone on Stack Overflow. I had no idea the site was populated by only teenagers.
Post reply on HN