4 ms·
> When they checked the login being used, they discovered an employee's credentials were being used on days he wasn't scheduled to work.
by 2arrs2ells 9y ago
> When they checked the login being used, they discovered an employee's credentials were being used on days he wasn't scheduled to work.
- kazagistar 9y agoThat's what happens when you don't have layered security. MAC address whitelisting, crytographic hardware tokens, 2fa, etc all would have stopped it dead in its tracks, but someone decided a login screen would be "enough".
- walrus01 9y agoOr even just 802.1x on LAN ports.
- amelius 9y agoYes, but it's easy to find effective countermeasures after the fact.
- kazagistar 9y agoThe point is that if you have multiple layers of countermeasures, then as long as one of them works you are OK. Too often are people willing to just rely on their one defensive layer.
- walrus01 9y agoIf it's a state government running the LAN at the prison they've failed to implement really basic standard LAN security measures like keeping ports down until they're actually in use by a known desktop PC or WAP, 802.1x, etc.