4 ms·
> "Cantor Fitzgerald did have extensive contingency plans in place, including a requirement that all employees tell their work passwords to four nearby colleagu
by john_b 12y ago
> "Cantor Fitzgerald did have extensive contingency plans in place, including a requirement that all employees tell their work passwords to four nearby colleagues."
This baffles my mind. Is this common practice in finance? What would stop a malicious actor from impersonating someone whose password they knew? Even if these passwords aren't tied to someone's identity in any way, they presumably exist to secure sensitive data and/or systems, but then they're shared with officemates like Dilbert comics?
- ryan-c 12y agoSecret sharing systems are a good solution to this. I wrote a basic command line only one[1] a few years ago, but command line UI doesn't really make for "usable by everyone". It would be nice if there were something like this that had a good UI. 1. https://github.com/ryancdotorg/threshcrypt https://github.com/ryancdotorg/threshcrypt
- pwnna 12y agoFor the purpose at hand, having some secrets accessible by multiple parties without sharing the same password comes in handy[1]. I'm surprised that this is not a feature of a lot of software that relies on encryption with keys based on passphrases. [1]: example: https://code.google.com/p/cryptsetup/ https://code.google.com/p/cryptsetup/. I believe that the way it works is it encrypts the actual decryption key for data with keys derived from passphrases multiple times, so any one of the those passphrases can decrypt the key, which then can access the data.
- peter303 12y agoOur company has interesting contradiction in this regards. On one hand all accounts, files and digital communication belong to the company. Assume you could instantly lose access in a sudden layoff. On the other hand the annual IT security video course tells you encrypt like crazy and leave no digital assets in public.
- hackuser 12y agoThey don't have a master cryptographic key?
- hackuser 12y agoAgreed. They might as have everyone use the same password. Aren't there regulations for security of financial information? It's hard to believe this passes muster. If it's a 'reasonable precautions' regulation, this fails badly.
- perlgeek 12y agoIt provides perfect deniability. Whatever you do in the computer system, there were four others who might have done it in your stead.