Given the fair assumption that any piece of data you give to a third party system that has access to the internet will eventually be breached, I feel like we need an entirely new system for data sharing. The problem with most of these hacks isn't usually so much that the hacked system itself has lots of valuable data, but that the data from the hacked system can be used to hack into other systems that do have valuabl…
Breach affecting 1M was caught only after hacker maxed out target’s storage
11–20 of 35 posts
Re: Breach affecting 1M was caught only after hacker maxed out target’s storage
#12plaintext passwords in 2019 .. it hurts to read articles like these.
These are often found in log files when people get a bit to log happy. I've seen many smart developers accidentally log a request in an API that also happens to show the login credentials.
Re: Breach affecting 1M was caught only after hacker maxed out target’s storage
#13storing these in plain text violates PCI-DSS
Re: Breach affecting 1M was caught only after hacker maxed out target’s storage
#14Earlier quoted context omitted.
These are often found in log files when people get a bit to log happy. I've seen many smart developers accidentally log a request in an API that also happens to show the login credentials.
Even Google fell for that one recently.
Re: Breach affecting 1M was caught only after hacker maxed out target’s storage
#15plaintext passwords in 2019 .. it hurts to read articles like these.
These are often found in log files when people get a bit to log happy. I've seen many smart developers accidentally log a request in an API that also happens to show the login credentials.
Re: Breach affecting 1M was caught only after hacker maxed out target’s storage
#16>full payment card numbers storing these in plain text violates PCI-DSS
Re: Breach affecting 1M was caught only after hacker maxed out target’s storage
#17Given the fair assumption that any piece of data you give to a third party system that has access to the internet will eventually be breached, I feel like we need an entirely new system for data sharing. The problem with most of these hacks isn't usually so much that the hacked system itself has lots of valuable data, but that the data from the hacked system can be used to hack into other systems that do have valuabl…
Re: Breach affecting 1M was caught only after hacker maxed out target’s storage
#18>full payment card numbers storing these in plain text violates PCI-DSS
The article doesn't say that they were stored in plaintext. Still a PCI violation though!
"... stored consumers’ personal information, including consumers’ SSNs, payment card information (including full or partial credit card and debit card numbers, CVVs, and expiration dates), bank account information (including account and routing numbers), and authentication credentials such as user IDs and passwords, in clear, readable text on InfoTrax’s network."