4 ms·
Encrypted? Encrypted how? How would the employees tasked with age verification access them if they were encrypted?
by naldb 1y ago
Encrypted? Encrypted how? How would the employees tasked with age verification access them if they were encrypted?
- jvanderbot 1y agoBy decrypting them with a hardware token or passphrase or memorized password or timeboxed token of another kind. But honestly just delete them ASAP, that's the issue
- Dylan16807 1y agoAnd if all the employees have access to this hardware token or passphrase or memorized password or timeboxed token of some kind, does that actually prevent a hack, or does it just let you bullet point "encrypted"? The main thing encryption prevents is someone that steals a physical device getting access to the data inside. It doesn't do much about unauthorized access to live servers.
- awesome_dude 1y agoI mean, this is the problem for all companies with sensitive data (ensuring that "ex" employees no longer have access to <stuff>). Generally it's done via accessing some 3rd party secret storage system where employees need to verify themselves to get access (eg. Vault, or AWS secrets or what have you)
- Dylan16807 1y agoDo you think this breach had anything to do with ex-employees retaining access? That also sounds like solving the wrong problem.
- awesome_dude 1y agoI mean this is posted on this page too. z> nomilk 8 minutes ago | prev | next [–] > The hacker claims an outsourced worker was compromised through a $500 bribe Also interesting: > The hacker claims government IDs were just sitting there for months or even years... I have spoken to people familiar with Discord's Age Verification system, and they said after some period of time Discord will delete (the copies of IDs), but they should be deleting them the second they're done Source (pinned comment, and 7m20s respectively): https://www.youtube.com/watch?v=NnuyT8FgSpA https://www.youtube.com/watch?v=NnuyT8FgSpA reply
- deleted 1y ago[deleted]
- vehementi 1y agoCheck out Defense in Depth as a security concept
- Dylan16807 1y agoIt's not defense in depth, it's defense against a different threat entirely. You want to have encryption, but I doubt their encryption or lack thereof has anything to do with this attack. Do we even have evidence the data wasn't encrypted?. If someone gets access to a ticketing system they shouldn't have, talking about encryption is about as useful as talking about seatbelts. Important for general safety but irrelevant to the problem at hand.