3 ms·
This is the whole "shadow IT" that actually results in a lot of security breaches. Look at the recent twitter hack for a great example. Staff were storing login
by shiftpgdn 6y ago
This is the whole "shadow IT" that actually results in a lot of security breaches. Look at the recent twitter hack for a great example. Staff were storing login credentials in a slack pinned message because using the right tools were a headache.
- alibarber 6y agoOne thing I despise is internal systems with self signed certs because setting it up properly is a faff or no one can agree on the latest and greatest way to do it. Oh cool that’s fine I’ll just click away all the big scary warnings in my browser to access this page. I’m an engineer and know what I’m doing! It’s a super strong key anyway. Oh wait I’ll just send this link to Bob in accounting and tell him to do the very thing we’ve been telling users not to do under pain of ridicule for ages and then he’s now doing that 10 times a day and now all of https is pointless because he knows that ‘it’s probably fine to ignore it because I have to do that at work’...
- outworlder 6y agoI have tried (unsuccessfully) to argue this point at a previous employer. Email server certificate expired and IT sent messages teaching people to ignore cert validation errors.
- baobabKoodaa 6y agoPart of the blame here should go to web browser developers. Self signed certificates pop up a huge warning while plaintext http connections do not, even though the former is more secure than the latter.