6 ms·
While there's a lot of security firepower in Israel, talent tends to gravitate towards high paying and/or technologically interesting companies. a consulting f
by ozkatz 7y ago
While there's a lot of security firepower in Israel, talent tends to gravitate towards high paying and/or technologically interesting companies.
a consulting firm developing one-off mobile apps used by political parties can offer neither (see the recent Iowa caucuses debacle)
- bsaul 7y agoi'm sorry but the person who had the idea of exposing an api endpoint to get admin user and password in cleartext (and for something related to politics above that) hasn't ever set foot in a computer science class. The level of incompetence required to commit such a fault is beyond what i would expect from any "third world" country. So, the fact that it happened in a country that advertize itself as a startup nation, and is exposed to one of the highest level of terrorist threat in the world is beyond my comprehension. If i were israeli i would recognize this event as one of the most damaging one of the last decade in term of public image. Israel has a huge flourishing business related to cybersecurity, mostly based on the reputation the country has for having the best specialists. If you know anything about business, you know how much image is important, and how this issue should be treated as a PR disaster for the whole country.
- deepspace 7y agoAgree, but I am going to make a prediction about what will happen to the executives of the company responsible for releasing this atrocious API. Absolutely nothing. They are going to continue to operate with nothing more than a slap on the wrist at worst. And that is why applications dealing with sensitive data are still being produced by people with no clue about security. Because there are never any consequences for leaking sensitive data, there is zero incentive for companies to spend the money on hiring competent developers.
- techslave 7y agothe person? the level of process incompetence that would allow such a defect beggars belief. my vote is that this was intentional.
- vkou 7y ago> i'm sorry but the person who had the idea of exposing an api endpoint to get admin user and password in cleartext (and for something related to politics above that) hasn't ever set foot in a computer science class. I've set foot in ~20 computing science classes, out of a ~134 credit-hour degree, and only one optional class ever mentioned that this sort of thing would be a bad idea. It also didn't actually rigorously teach best practices, only mentioned a laundry list of security blunders that you probably want to avoid, without proscribing any solutions. We also were not tested on this. And this degree wasn't in some middle-of-nowhere community college. Also, as anyone who has ever set foot in a computer science class ought to know, these kinds of failures aren't the fault of any one person. One person may be undereducated, ignorant, lazy, stupid, or just in a hurry to ship. It's the entire organization's responsibility to provide checks and balances that prevent this sort of thing from hitting production.
- theflyinghorse 7y ago> ... but the person who had the idea of exposing an api endpoint to get admin user and password in cleartext .... I'd be hesitant to call out one person. A process failed. Where were the code reviews, design sessions, pentesters, QA, UAT, automated tests?
- bsaul 7y agoin some cases no particular individual are able to see something's wrong, and only someone with a general overview of the system can see the pb. in this case, every single individual in the chain ( from backend dev to frontend dev to tester to enduser) are able to see that something's very wrong. Which means none of those people are competent. Not any of them.