Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

11–20 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#11
post #5

To be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.

> my employer recently bought another outfit that does that does just that [leaves passwords in cleartext], and fixing it is not a near term option

Could you expand on why not? I can't think of a good reason why this isn't a relatively quick fix. What's the blocker?

Re: 'Impossible-to-hack' security turns out to be no security

#12
post #5

To be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.

Some powerful people subscribe to the idea that "if I (or the law) says don't touch it, it's secure". This attitude was on full display a little over three years ago in Missouri. https://missouriindependent.com/2021/10/14/missouri-governor...

Missouri

Re: 'Impossible-to-hack' security turns out to be no security

#14
post #11
post #5

To be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.

> my employer recently bought another outfit that does that does just that [leaves passwords in cleartext], and fixing it is not a near term option Could you expand on why not? I can't think of a good reason why this isn't a relatively quick fix. What's the blocker?

(not op, just hypothesising)

> I can't think of a good reason why this isn't a quick fix.

What if there's some IoT product with no update mechanism and the access password to function is stored on all of them in plain text?

Re: 'Impossible-to-hack' security turns out to be no security

#16
post #14
post #11

Earlier quoted context omitted.

> my employer recently bought another outfit that does that does just that [leaves passwords in cleartext], and fixing it is not a near term option Could you expand on why not? I can't think of a good reason why this isn't a relatively quick fix. What's the blocker?

(not op, just hypothesising) > I can't think of a good reason why this isn't a quick fix. What if there's some IoT product with no update mechanism and the access password to function is stored on all of them in plain text?

Possibly, but that's a very different scenario to a database of cleartext passwords (which is what I assumed was meant), as each device would have to be identified and compromised to access a password to a device which at that point is already compromised...

Re: 'Impossible-to-hack' security turns out to be no security

#17
post #11
post #5

To be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.

> my employer recently bought another outfit that does that does just that [leaves passwords in cleartext], and fixing it is not a near term option Could you expand on why not? I can't think of a good reason why this isn't a relatively quick fix. What's the blocker?

It requires programming in a language specific to one little known db product, in an extremely brittle and spaghettified code base . There's exactly one person in the company who kinda knows how to do it, and they're unavailable for the foreseeable future on higher priorities. We don't have the money to throw at new hires or huge porting projects.

Imagine software that has been in production since the 80's, was written by a very inexperienced dev and has since been continually "organically" upgraded to handle any new promise that a nontechnical product manager feels is necessary to solve the immediate problem of an angry customer. It's a Jenga tower with a reset button.

Re: 'Impossible-to-hack' security turns out to be no security

#18
post #11
post #5

To be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.

> my employer recently bought another outfit that does that does just that [leaves passwords in cleartext], and fixing it is not a near term option Could you expand on why not? I can't think of a good reason why this isn't a relatively quick fix. What's the blocker?

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#19
The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Re: 'Impossible-to-hack' security turns out to be no security

#20
post #15

Not very polite or understanding. Wants to be helpful but comes across as aggressive, names and shames them, insults and ridicules them... come on, you can do better.

OP here, the one who found the exposed data.

Not sure if you read my 2 emails to the company but I would say I was polite to them and was met with accusations of harassment and straight up lies.

Don't expect me to pat you in the back if you come at me with such claims when I simply alerted you of a security issue.

Post reply on HN