6 ms·
I worked at a healthcare company in the US (we provided HIPAA data connections between insurance and providers) and discovered all the production passwords were
by coldcode 7y ago
I worked at a healthcare company in the US (we provided HIPAA data connections between insurance and providers) and discovered all the production passwords were storied in a text file in the code repo half the company had access to. The CTO told me "we trust our employees". There was also no auditing on who access the DB and servers, and they never changed the passwords because the chief architect did not want to remember anything.
- rpmisms 7y agoDid you work at my current company? Because that's Exactly what happens here. Also, I'm so sorry you had to touch EDI, if you did.
- SamuelAdams 7y agoI worked at a retailer (not Target) that did something similar. Once Target got breached in 2014, they mandated security training and began making changes to some things in the org. This was one - instead of storing those passwords in plain-text, they were encrypted. So people encrypted them, commited them into the repositories, and deployed the now encrypted files to production. Cool, right? They didn't actually change the passwords, since that would break too many things at once. So you could just look at the git history to get the plain text password. Or debug the application locally. Security theater all day. Sigh.
- EnderMB 7y agoThere's something both comforting and absolutely terrifying that everyone has similar stories of software negligence. I would love to see a whistle-blower company formed, where you could report software engineering malpractice, and be compensated and/or protected from being punished. Not necessarily a union, but an industry body that could verify your security concerns and either "out" a company for punishing you, or provide you x months of work and a reference to compensate the termination of your employment.