Post #3134777
2024-01-18 12:55 UTC
Replies (3)
-
@thisismissem@hachyderm.io 2024-01-18 12:58
@WPalant@infosec.exchange in this case it just sounds like he used the key to open the front door, saw an absolute mess & notified the company of the issue
-
@tklengyel@discuss.systems 2024-01-18 13:22
@WPalant@infosec.exchange @thisismissem@hachyderm.io Intent and damages should absolutely matter. But it's also common sense not to use the hardcoded credentials to login and dump the database. Or if you do, why report that you did? Perfectly sufficient to just say you found the hardcoded credentials and stop there.. Bad practice on both sides.
-
@pierstoval@mastodon.social 2024-01-18 14:46
@WPalant@infosec.exchange @thisismissem@hachyderm.io Many judges in court don't know jack shit about programming, and "compiling" is the same as "encrypting" for them. As many analogies said: if you give someone the key to your house, whether it's wrapped in tons of cardboard and tape, they still have the key. The software provider must be condemned as a security flaw, endangering all users.