5 ms·
>>Most banks don't make any security demands of internal applications because they are not accessible to the internet. At which point safety is just a way to sl
by smtddr 11y ago
>>Most banks don't make any security demands of internal applications because they are not accessible to the internet. At which point safety is just a way to slow you do.
This is a bad way of doing things. That means as soon as someone finds a way to get inside the network, the bank is wrecked. You need to look at security from the point of assuming the attacker somehow got inside because it'll happen one day.
http://digg.com/2015/ashley-madison-hack http://digg.com/2015/ashley-madison-hack
"""
MOTHERBOARD: How did you hack Avid Life Media? Was it hard?
The Impact Team: We worked hard to make fully undetectable attack, then got in and found nothing to bypass.
MOTHERBOARD: What was their security like?
The Impact Team: Bad. Nobody was watching. No security. Only thing was segmented network. You could use Pass1234 from the internet to VPN to root on all servers.
"""