Follow

@dangoodin Yeah, if your system fails and your solution is "well, we'll just make sure no one ever makes a mistake again" that...isn't really a solution at all.

I mean, I know that they did make other changes, but trying to focus on the poor judgement of the individual just to me betrays the wrong mindset.

@dangoodin To my (largely untrained) eyes, some big red flags seem to be
1. They didn't have an intrusion detection system that flagged this (it seems like a new IP/host accessing a service account from likely a new subnet would be notable) and it sounds like they only found out once their customers notified them.
2. Relying on password-based authentication rather than key/certificate-based authentication for remote access to a service account without strong compensating controls (like limiting it to specific hosts)
3. Once they knew their customer had been breached they couldn't just look at the access logs for the affected account and verify in short order that there were hosts for which they couldn't account.

But I'm curious what those with more knowledge think on those points.

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.