4 ms·
Funny enough I used to work for a water system in the “Information Systems” department - there was far too much of the classic “not my problem” from colleagues.
by antonymoose 2mo ago
Funny enough I used to work for a water system in the “Information Systems” department - there was far too much of the classic “not my problem” from colleagues.
Our original bill pay (ran from 2006 to 2019) stored passwords in plaintext in flat files. Concerned citizens noticed because our password reset would just email you your own password. Instead of fixing it, they just removed the ability to recover an account without coming into an office. Our CTO knew, he wrote the whole thing!
We had a fun one, Outlook was sending employee passwords to our bill pay system and ending up plaintext in our logs due to some quirky fallback default behaviors around DNS and VPNs. Reported and ignored, of course.
Regarding TFA, we had an insurance requirement to properly air gap our PLCs - which we didn’t do. We (the CTO) just put them on a separate subnet and lied to insurance.
There’s not much you can do to an organization that has no real oversight here, especially once the “coast to retirement” types infest the place. We need something like HIPPA or PCI-DSS with real auditors and real teeth for utilities.