Hacker News new | ask | show | jobs
by freehunter 3265 days ago
Ugh, when I was a security analyst for an enterprise, I'd occasionally have Network Solutions call me and try to sell me certificates. I'd explain that it's not my decision, you've got the wrong person, how did you get this number and turns out they'd call the front desk or the help desk and say they found a security hole on our public facing websites. The security hole was that we used another company for our certs.

The real security hole was that the operators were patching through salesmen directly to the security staff without verifying who they were...

1 comments

Yes, the real security hole was 'operations' not sufficiently validating credentials and being a proper gatekeeper.