24 ms·
I'd be curious to hear some anecdotal stories like this, would you share :)
by daddykotex 10y ago
I'd be curious to hear some anecdotal stories like this, would you share :)
- jacquesm 10y agoI'd love to, however the penalties on breaking the NDA's are somewhat higher than my net worth, and besides my reputation and continued employment is worth more to me than satisfying the curiosity of your average forum visitor. That said, the insights I've gained over the last couple of years have made me very wary about anything stored in databases concerning myself and the rest of the general public. Let's just say that Snowden only exposed the tip of the proverbial iceberg and that one day the truth will likely come out because of some horribly insecure entities being hacked (if it hasn't already happened) with massive exposure of people in positions of power as a result. The more you look behind the curtain the longer you are amazed that it is still being held up.
- daddykotex 10y agoall right, all right, thanks anyway
- pavel_lishin 10y agoI'm not jacquesm, but one I always like to share is a client who would store credit card data - numbers, addresses, expiration dates, and cvvs (yes) - in plain text in a database, in plain violation of PCI compliance and common sense. We kept telling them that this was a bad idea, that it wasn't compliant, that it was dangerous, that they could lose their ability to process credit cards at all at best, and lose their entire database of customer credit card numbers at worst. But there was no money in the budget for this kind of refactoring. Until the data was exfiltrated via a trojan. Suddenly, there was money in the budget.
- jacquesm 10y ago> Suddenly, there was money in the budget. But the horse had already bolted.
- gargravarr 10y ago>Suddenly, there was money in the budget. Was this before or after the lawsuit? Assuming there was one (which there really needs to be...)