Looking through public password dumps is weird. Like, I'm pretty sure I know the password that the CEO of a >$1billion corporation uses for everything. Not touching it with a 10 foot pole because it's none of my business, but...
-
Show this thread
-
Replying to @marcan42
You would suspect that they have an RSA token or something of a smartcard in their laptop. Or fingerprint or Windows Hello or something else.
1 reply 0 retweets 0 likes -
Replying to @W00fer
You severely overestimate the security of most companies.
1 reply 0 retweets 4 likes -
Replying to @marcan42
Well I see multinationals at uni presenting theirselves with company laptops which are quite ok secured. What worries me more is the BYOD movement without proper patching. For smaller firms it could be as worse as writing passwords in sticky notes which are viewable from outside
1 reply 0 retweets 0 likes -
Replying to @W00fer
I've seen admin panels and infrastructure dashboards behind HTTP Basic auth out open on the internet, on HTTP, no encryption.
2 replies 0 retweets 1 like -
Replying to @marcan42
Why don't you inform the CEO under responsible disclosure agreement?
1 reply 0 retweets 0 likes -
Replying to @W00fer
Like I'm going to risk that. As I said, I'm not touching it with a 10 foot pole. It's the company's security staff's responsibility to peruse lists like this (and I'm sure they don't, and that's their problem).
1 reply 0 retweets 1 like
I already have my hands full enough convincing the companies that *actually* pay me for this stuff to take things seriously ;).
-
-
Replying to @marcan42
Sounds like a job for me. With a lower fee per hour I can advise the easy stuff ;)
0 replies 0 retweets 1 likeThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.