3 ms·
How could a stolen session token even be useful. I have to log into tools every day, if I change IPs at all I have to re-authenticate, and all prod access needs
by StopHammoTime 4y ago
How could a stolen session token even be useful. I have to log into tools every day, if I change IPs at all I have to re-authenticate, and all prod access needs to be approved and has a finite lifespan.
How could a CI company be that negligent. They should be leading this stuff from a best practice point of view.
- m00x 4y agoThe employee had malware on his computer, and the hackers might've used a VPN that's located in a "safe" zone. Security is pretty lax at most companies, and the more employees you have, the worse it is.
- shamiln 4y agoMost places I’ve worked, has the concepts from above. Security is lax at most companies but even having worked as an engineer on support rotation, customer anc production access was the last thing I could do and I needed to have exhausted all other options. I don’t feel retaining production access to generate tokens should be a thing.
- m00x 4y agoIt depends on the eng. If you're a senior eng with on-call responsibilities, you're getting full time prod access.
- hveragerdi 4y agoNo need for a VPN if you have access to the laptop, you just use that as a proxy. Look at any c2, open source or commercial, and they'll have that as a feature.
- deleted 4y ago[deleted]
- eurasiantiger 4y agoHard agree. A stolen token was still valid a week later! There is no excuse.