3 ms·
A social engineer wouldn't try for this much data. One SSH key or password would be enough. I'm going with the fucking-retarded-auditor theory.
by d2 15y ago
A social engineer wouldn't try for this much data. One SSH key or password would be enough. I'm going with the fucking-retarded-auditor theory.
- w1ntermute 15y agoThen again, it could be a social engineer trying to play off the commonly-held belief that an actual social engineer wouldn't ask for something so blatantly illegal.
- SeoxyS 15y agoYou think too much. Usually, the simplest explanation is also the correct one. I put my money on retarded auditor who thinks he's more clever and powerful than he is.
- w1ntermute 15y agoIt never hurts to be careful. When it comes to security, defense requires closing all possible holes, while offense requires finding only one. It would be irresponsible for the employee not to at least be cautious when dealing with this auditor. It's worth taking a few minutes to call the company performing the audits and verify that the auditor is who he says he is.
- Retric 15y agoIMO, that should actually be part of the process of passing a security audit. Which suggests someone who is doing an audit will ask for information that if given to him will cause you to fail the audit.
- dspeyer 15y agoConfirming that he is an auditor is insufficient. A sufficiently clever legitimate auditor might attempt social engineering attacks and fail you if they succeed. In fact, this seems like a more effective way to sniff out plaintext password storage than saying "show me everywhere you touch passwords and how they're encrypted".
- Retric 15y agoSorry, if I was unclear. Confirming that he is an auditor should be a checkbox in an audit as should be limiting the information provided to an auditor. While I like your idea that it would show if they could get access to users passwords even handing out the salted password list is a bad idea. One of the more interesting government audits I have heard about was the auditor did a basic internal audit and said he was part of physical secuity ect so people knew he was part of the audit team. He then showed up late, turning off the power supply to the building and then pointing at people who show up at the generator and saying "bang your dead" this is part of an audit etc. If they failed to call security before everyone was "dead" they where considered to have failed that part of the audit. He also attempted to get into the building without showing up on camera's ect. All of which sounds like a fun job and a good idea.
- deleted 15y ago[deleted]
- shaggyfrog 15y agoIn the same way, shoplifters would never try to steal anything larger than something they can fit in their hand. In reality, they walk out of retail stores with objects as large as kayaks everyday -- often with the assistance of store staff. Why? Because everyone assumes no way this guy isn't legit because a bad guy would never attempt something so blatant. Asking for everything might sound more legitimate than asking for one small thing. Perps generally go with their gut. In this case, this "auditor" shot for the moon with the wrong mark.