Hacking into an insurance company by exploiting their premium calculator
91–100 of 113 posts
Re: Hacking into an insurance company by exploiting their premium calculator
#92Earlier quoted context omitted.
The Peter Principle…people get promoted into incompetence.
We put peter there. He's doing the job we put him there to do.
I see your point, did you know it’s a book?
Dang
Harvard Business Review: https://hbr.org/2014/12/overcoming-the-peter-principle
Re: Hacking into an insurance company by exploiting their premium calculator
#93This takes "don't call us, we'll call you" to the next level: running a vast chunk of your business from the noreply@ account!
Re: Hacking into an insurance company by exploiting their premium calculator
#94Earlier quoted context omitted.
There is a huge missing niche for trusted intermediaries of identity information. We’ve been working on this at https://cerebrum.com in a different niche (background checks), but this comment just triggered a slew of ideas…
Lol 0/10 marketing push. Btw, schedule is spelt with a c after the s.
This isn’t a marketing push so much as an observation. Some company will fill this niche at some point. There is no reason to disclose your SSN to a car dealership if you can share a shielded, verifiable record of your credit history to them.
You can look through my comment history — I am not here to sell a product.
Re: Hacking into an insurance company by exploiting their premium calculator
#95Earlier quoted context omitted.
I think nowadays the blur feature just makes it look blurry, but it's not the actual original text being blurred.
How are we to know if someone didn't just use an affine transform? This is another place where ignorance could result in security leaks.
Re: Hacking into an insurance company by exploiting their premium calculator
#96I'm curious to know how this person decided to just go looking into the source code of this very specific app. Why this one?
Re: Hacking into an insurance company by exploiting their premium calculator
#97Earlier quoted context omitted.
> This is what you get, ladies and gentlemen, without unions and labour right. Are you speaking of the EU? The US has at-will employment and most software developers are not unionized.
Is it legal to have a 90 day salary clawback (not a signing bonus clawback, just salary clawback for quitting) in the US?
Re: Hacking into an insurance company by exploiting their premium calculator
#98Earlier quoted context omitted.
How are we to know if someone didn't just use an affine transform? This is another place where ignorance could result in security leaks.
Yeah I'm not fucking around with that. Solid block of black removes the guesses. (Caveats for layered documents like PDFs).
Re: Hacking into an insurance company by exploiting their premium calculator
#99Earlier quoted context omitted.
https://www.enforcementtracker.com/ Here's a long list of them
Not really. That links to a list of all enforcement actions. If you search for "technical" you get "organisational and technical measures", and most are organisational rather than technical. If you search by the word "hack" which seems to be the seems to be the usual terminology used there for vulnerabilities being exploited. There are 18 of these of 2182 entries. Not even one per EU country since 2018. Given how com…
Here's a few famous ones, most of which are of course a few years old since government agencies tend to move slow but more recent ones will get what's coming for them.
https://www.theguardian.com/technology/2022/nov/28/meta-fine...
https://ico.org.uk/media/action-weve-taken/mpns/2618524/marr...
https://en.wikipedia.org/wiki/British_Airways_data_breach#Co...
Re: Hacking into an insurance company by exploiting their premium calculator
#100The security blunders are obviously horrible, but MAYBE explained by inexperienced developers tasked with something way beyond their understanding. But how on earth did anyone approve storing confidential customer documents in an email account? This seems to indicate there's nobody in charge that understands anything about how to run this business. And if it's a subsidiary or outsourcing partner, it also shows that n…
I saw a fairly large estate agency system that bcc’d every outgoing email from their system to a shared account everybody then synced to Outlook. It was part audit log, part debugging tool, part database backup. They changed when they realised employees were taking all their customers’ details to new jobs.
A friend who's taken Visa's data confidentiality training several times notes that customer data is secondary to Visa's own marketing campaign details.