3 ms·
I agree, if Zoom isn't capable of handling #2 or #3 on the list, then #4 is irrelevant to them. You would think that "not storing cleartext passwords" is a uni
by netsectoday 6y ago
I agree, if Zoom isn't capable of handling #2 or #3 on the list, then #4 is irrelevant to them.
You would think that "not storing cleartext passwords" is a universal given today, but the corporate structure controlling software design today actively suppress anything that isn't a feature. It silos security responsibility to the point where nobody was probably in charge of making sure there was a coherent password policy, that it conformed to any type of standard, or that it was enforced in production against their multiple running systems.
This is every company today.