Live data from Hacker News

Hackers shoveled snow for company, were rewarded with network admin access

theregister.com

11–20 of 81 posts

Re: Hackers shoveled snow for company, were rewarded with network admin access

#11
post #5

Earlier quoted context omitted.

1. Open a web browser and do a search 2. Read until you find a sentence that you like. 3. Use it as your password

Not enough numbers or special characters usually.

I loathe two things in password requirements: special characters and not allowing spaces. C'mon, it's 2026. Require 20 characters and call it a day.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#12
post #2

”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.” Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so… The better idea is to require pa…

[deleted]

Re: Hackers shoveled snow for company, were rewarded with network admin access

#13
post #5

Earlier quoted context omitted.

1. Open a web browser and do a search 2. Read until you find a sentence that you like. 3. Use it as your password

Not enough numbers or special characters usually.

Use one specific special character/number as word separator.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#14
post #6

The company also should have restricted network access to the port in the conference room so that an unknown device like a Raspberry Pi could not make an Ethernet connection from that spot Bad take - the actual problem is that there was a trusted network in the first place. This kind of network access control is trivial to bypass, and trusted devices can get compromised.

It's not my field, but at least at my work the network can somehow tell the difference between an authorized user and not. It is not simply using the MAC address.

A guest device connected to the ethernet port in the conference room has the same access as a device connected to the guest wifi, a staff laptop has it's usual access.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#16
post #4

Earlier quoted context omitted.

1. Open a web browser and do a search 2. Read until you find a sentence that you like. 3. Use it as your password

I like the last line of your comment My password is now password

Should have been "use it as your password"

Re: Hackers shoveled snow for company, were rewarded with network admin access

#17
post #2

”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.” Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so… The better idea is to require pa…

Letting users pick their own passwords has always been a mistake. If passwords are needed, the system should choose them.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#18
post #11
post #5

Earlier quoted context omitted.

Not enough numbers or special characters usually.

I loathe two things in password requirements: special characters and not allowing spaces. C'mon, it's 2026. Require 20 characters and call it a day.

"password is to long, max length..."

(╯°□°)╯︵ ┻━┻

Re: Hackers shoveled snow for company, were rewarded with network admin access

#19
post #17
post #2

”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.” Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so… The better idea is to require pa…

Letting users pick their own passwords has always been a mistake. If passwords are needed, the system should choose them.

just directly give them a post-it for their monitor

Re: Hackers shoveled snow for company, were rewarded with network admin access

#20
Being overly suspicious of everyone is a terrible way to live. Maintenance should have the autonomy to do as they did here - and security correctly followed up. The right response should only be technical imo. A meeting room should not lead to this level of network access.
Post reply on HN