Hacker News new | ask | show | jobs
by hackinthebochs 29 days ago
If the credentials are stored for some period of time, then an inspection will reveal those stored credentials within the preservation window. Unannounced inspections will then show with high certainty a legitimate validation process.

The auditor can act as a customer and validate whether phony credentials are rejected.

1 comments

Thanks for agreeing with me?
I thought I was elaborating on how to minimize exposure. If this is just what you meant, then sure!
Yeah, my point is that there is a significant exposure they are required to have, if they need to be able to be audited and have to actually prove they are dealing with real people.

At least - as you mention - until the rules catch up and there is some sort of one way hashing/signing or something possible, which for most of these industries is probably decades away (if ever). Most of these industries struggle with photocopies at this point.