Live data from Hacker News

Hackers shoveled snow for company, were rewarded with network admin access

theregister.com

51–60 of 81 posts

Re: Hackers shoveled snow for company, were rewarded with network admin access

#51

Being overly suspicious of everyone is a terrible way to live. Maintenance should have the autonomy to do as they did here - and security correctly followed up. The right response should only be technical imo. A meeting room should not lead to this level of network access.

Agreed! As a friendly favor, could you please post your full name, ZIP code, credit card number, and the 3 digit security code on the back?

- Love and peace, your neighbor on HackerNews

(which is to say, I think you know that you can be friendly without being foolish - but if not I'm going to really enjoy the gift of that credit card :))

Re: Hackers shoveled snow for company, were rewarded with network admin access

#52
post #38
post #28

Earlier quoted context omitted.

Expiring passwords and length limits. Why can't my password be a 5KB long? My password manager has no limits. Are people storing them in plain text in 2026?

I ran into a website for work that would let you create a long password, but silently truncate it to 12 characters before saving. Mind boggling.

Blizzard/battle.net used to do this (still does?), lol

Re: Hackers shoveled snow for company, were rewarded with network admin access

#53
post #10

What always gets me about these red team attacks is the same thing that gets me about internal phishing test emails. My company sent an internal phishing test last week. Several people immediately reported it to a cybersecurity engineer, posted about it in Slack, saying they were surprised that such a sophisticated phishing attack was happening. I too was surprised - Google is usually much better about catching these…

"Theoretical" becomes "pretty much guaranteed" if standards sink low enough - the more effort you put in, the more problems you ward off.

Sort of like how a lock can be picked in 30 seconds, but still deters 90% of crime - a lot of criminals are just searching around to find out who is vulnerable, and most every company has something that's worth at least a bit (even if it's just stealing $500 laptops instead of breaching the network)

Re: Hackers shoveled snow for company, were rewarded with network admin access

#54
post #28
post #24

Earlier quoted context omitted.

Expiring passwords are one of my biggest gripes, and I still see them everywhere

Expiring passwords and length limits. Why can't my password be a 5KB long? My password manager has no limits. Are people storing them in plain text in 2026?

> Why can't my password be a 5KB long?

Probably because that's just unnecessary. A few dozen characters is plenty, anything beyond that is just excessive.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#55
post #28

Earlier quoted context omitted.

Expiring passwords and length limits. Why can't my password be a 5KB long? My password manager has no limits. Are people storing them in plain text in 2026?

And content limits. Why can't my password contain the % character? No special characters? What makes a character "special"? Why can't it contain emoji? So many password systems go to great lengths to remove potential entropy and randomness from passwords with their rules. The usual excuse is "blah blah blah legacy systems" which is not a good reason.

Probably because there is some mildly decent reason (or very good, I don't know) to avoid them and it really doesn't matter enough to worry about getting around it.

Why would you want emojis in your password? It's a piece of text not meant to be seen, emojis are meant to be seen. Just randomly generate some characters and get on with your life. I don't understand why you care about this at all, it's such a pointless thing to complain about.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#56
Since they came in through an open door, a fake badge that passed quick casual visual examination would have seemed potentially helpful here. I'm surprised the pen testers didn't craft such badges. Perhaps it was difficult to get a sufficiently high res image of a real badge from an employee entering or leaving the facility (although, if the front desk is manned, it might be possible to walk up to the desk with an innocuous question and snap a pic of the receptionist's badge if it's visible)?

I've never worked anywhere that stressed keeping your badge concealed until the moment of entry and concealing it upon last "scan" point on exit. If followed, such a policy would slightly reduce the risk of fake, but visually adequate, badges -- but compliance with such a policy would probably be very low in most commercial situations.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#57
post #28
post #24

Earlier quoted context omitted.

Expiring passwords are one of my biggest gripes, and I still see them everywhere

Expiring passwords and length limits. Why can't my password be a 5KB long? My password manager has no limits. Are people storing them in plain text in 2026?

> Why can't my password be a 5KB long?

You should switch to Windows, Microsoft got you covered[1].

[1]: https://www.betaarchive.com/wiki/index.php/Microsoft_KB_Arch...

Re: Hackers shoveled snow for company, were rewarded with network admin access

#58
post #24
post #2

”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.” Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so… The better idea is to require pa…

Expiring passwords are one of my biggest gripes, and I still see them everywhere

One good thing about expiring passwords is that it forces you to use something that you probably don't use for everything else in your personal life.

Re: Hackers shoveled snow for company, were rewarded with network admin access

#60
post #38
post #28

Earlier quoted context omitted.

Expiring passwords and length limits. Why can't my password be a 5KB long? My password manager has no limits. Are people storing them in plain text in 2026?

I ran into a website for work that would let you create a long password, but silently truncate it to 12 characters before saving. Mind boggling.

I unfortunately had the infuriating experience dealing with a (government, of course) site that did this. To add to the experience, not only did it silently truncate at registration, but it did NOT truncate on the login fields. And of course, it has a lockout after several failed attempts. UX gore at it's finest.
Post reply on HN