4 ms·
If I'm reading this correctly, the real "hack" was stupid passwords like admin:admin, pos:pos on the POS machines. In which case, we need to hold management mor
by interstitial 13y ago
If I'm reading this correctly, the real "hack" was stupid passwords like admin:admin, pos:pos on the POS machines. In which case, we need to hold management more accountable for such lax password policies.
- pionar 13y agoI think these are default passwords, like routers. That's on the developers and IT people for not putting stronger passwords on these devices.
- derefr 13y agoYou know, I'm actually surprised we haven't solved this particular problem yet. We have autoconfiguration protocols for stupidly complex things, like UPNP. It's a wonder nobody has created either a daemon (to run on domain controllers), or a network appliance, which: 1. heuristically detects unconfigured/default-passworded L2/L3 hardware (e.g. routers) on the network; 2. generates and sets a strong password for that hardware itself; 3. proxies all further access to that hardware, keeping the password only between it and the captured devices (and hopefully delivered only over TLS, if that's possible); and 4. has actually-sensible security itself (e.g. using SSH keys, HTTPS client certificates, or any other non-repudiatable token type.) Effectively, it'd act as an automatic password vault and security gateway for all the devices too simple to have good security themselves.
- forgottenpass 13y agoI really like the idea, but if people aren't buying the vulnerability scanning appliances available today (that would just report the open devices), why would they start buying if one was for sale with the value-add you describe?
- derefr 13y agoBecause vulnerability scanning is a vitamin, not a painkiller. This type of thing addresses a specific pain--IT having to generate, keep track of, and manage access to[1] device passwords--and just happens to increase security as a side-effect. [1] This part is important. In most companies, whenever you have a tech leave who knew a password? You've got to reset that password. You might not even know which passwords they knew, so you have to reset everything to be safe. And then the passwords other techs have memorized are invalidated. Incredibly painful.
- 0xdeadbeefbabe 13y agoSo, that would have prevented the Target breach? Makes you feel sorry for the word hack.
- EvanAnderson 13y agoI can think of at least one product that will do, basically, what you describe. It's insanely expensive to license and setup. It would probably be feasible to fork the RANCID network device configuration version control application to create something that could do what you're describing out of FLOSS components, too.
- jonknee 13y agoI assume it's like the number of printers and CCTV cameras you can access--no one knew they were public. This doesn't appear to be the Target hack though, just some random IPs that had the default passwords on them.
- rlu 13y ago>> This doesn't appear to be the Target hack though Yeah it's not very clear to me either. Not sure if the relevant Target part is in the second IM transcript where ree4 seems to try and sell a special version of his product that CAN work with Verifones for 2000 USD?
- jreed91 13y agoFrom what I heard from a friend who use to work for Target IT is that they just had a massive lay off before this. More likely that someone intentionally left a back door open before they left.