4 ms·
I worked for a hedge fund where a quant dev emailed to his gmail a copy of the source for the quant models. He was sued in federal court 4 hours before he was
by hermitdev 7y ago
I worked for a hedge fund where a quant dev emailed to his gmail a copy of the source for the quant models. He was sued in federal court 4 hours before he was terminated. Criminal charges came around 2-3 months later, IIRC. Once he realized he was fucked, he tried dumping his hard drives in a river. Yes, police diving squad was involved.
Dumbass didn't realize that all SSL traffic was being MITM'd. I never sent any sensitive over personal email from work, being well aware of the practices (also helps to have friends in compliance).
- htrp 7y agoIt's always the dumb ones that get caught?
- Nuzzerino 7y agoDoesn't the browser display a warning in the case of SSL MITM?
- cdumler 7y agoNot if the browser has been specifically given the cert. It is typical on corporate networks send all HTTP traffic to a router that acts on behalf of the outside world. If your browser (and browsers these days relying on OS installed certs) has a cert validating the router, it will be legitimate: you have a valid cert for the router you're talking to. The trick is to use a piece of software that doesn't use your system's certs but has it's own built in, like run Linux in a VM and use that browser. That way, you'll see the MitM attack.