3 ms·
Many SaaS products, especially enterprise software, have a "login as a different user" feature that engineers use for debugging. It's good that non tech savvy u
by thejo 17y ago
Many SaaS products, especially enterprise software, have a "login as a different user" feature that engineers use for debugging. It's good that non tech savvy users aren't always aware of the amount of information leakage that happens in situations where privacy is important. It would lead to a mega freak out.
For example, if you receive SMS alerts from your bank about transactions, account balance etc. there are multiple engineers in the chain who have access to the information, but should not -
* At the SMS gateway company to which the bank has outsourced the services
* Your mobile service provider
* People who run the SMSC (if the mobile operator has outsourced that)
Unfortunately, there is no way to secure it end to end in its current form. The same is applicable to a lot of services.
- pyre 17y ago> Unfortunately, there is no way to secure it end to end in its current form How about supporting public key encryption for SMS? Oh sorry, I forgot that the government wouldn't like that too much. Everything should be out in the open so that everyone can view it to make it easier for law enforcement (at the same time making it easier for criminals to access the information of 'normal/average' people).
- thejo 17y ago> How about supporting public key encryption for SMS? The protocol in its current widely deployed form does not support it.