3 ms·
Failure to patch wasn't the cause of this breach. The causes of this breach were: 1. Reliance on a consumer-grade component in a security-critical system holdi
by eatboogers 9y ago
Failure to patch wasn't the cause of this breach. The causes of this breach were:
1. Reliance on a consumer-grade component in a security-critical system holding high-value data.
The portal should have had a small, audited code base with secure coding techniques and minimal reliance on third-party components.
2. Excessive attack surface on a system holding high-value data.
The machine hosting the portal should never have had read access to SSNs. Sensitive data should have been "thrown over the wall" to a secure backend with a constrained interface. This would have greatly reduced the scope of the breach.