| I’ve seen Optus “computer security” in action. I use quotes for a reason. There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a previous breach. You see, until a judge made them do it… they weren’t patching anything. They would just build systems and walk away. For some software systems they had every major and minor version deployed, like a museum of software history. They had operating system versions in production that were in my university text books… in the late 1990s. Their interpretation of the court order was to update only production systems. Non-production on the same network was not to be touched. And by “update” they meant simply running the system update tool, which does precisely nothing on software that has passed its end-of-extended-support before some of the IT staff on the payroll were born. They also fired their entire IT staff recently and replaced them with a low-cost Indian outsourcer. Most of the above is a matter of public record. I wish I could tell you all about things that are still under NDA. |