Hacker News new | ask | show | jobs
by josephwegner 4187 days ago
Apparently they hired these guys to help with "protection against cyber attacks"

http://www.conosco.com/case-studies/moonpig-outsourced-it/

Awful...

2 comments

It's worth pointing out that the case study is from 2007, there's a good chance that this company is no longer involved and likely wasn't involved in building the API for apps and the security on them.
In any case, once this is out, they will have to take the Moonpig case study from their site.
Yup that link is now 404
Their first "solution": Fixed price outsourced IT department
To be fair, the complete security failure outlined in the article is at the app level and not something I'd expect most IT departments to bear responsibility for (unless they were directly consulted about how good of an idea using basic auth with hardcoded credentials is and gave an OK on it).

Of course, I wouldn't be too surprised if the app/API here were also outsourced to a low fixed price development shop.