A case study in why credentials are revoked before firings.

you are viewing a single comment's thread
view the rest of the comments
[–] 174 points 4 months ago (21 children)

Why were they storing passwords in plaintext in the databases?!

  • source
  • hideshow 21 child comments
  • [–] 50 points 4 months ago (3 children)

    Why not? National Safety Department of Slovak Republic (Narodny Bezpecnostny Urad) had password NBUSK123… just government things

  • source
  • parent
  • hideshow 3 child comments
  • [–] 44 points 4 months ago (6 children)

    Because like all critical infrastructure it was setup by somebody's kid on work experience

  • source
  • parent
  • hideshow 6 child comments
  • [–] 20 points 4 months ago (5 children)

    Or some poor guy who is setting it up, because it is a one off and just get it done project, that metastasizes into a fucking mess.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 7 points 4 months ago (4 children)
  • [–] 5 points 4 months ago (3 children)

    All contracts go to the lowest bidder.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 18 points 4 months ago

    It's like leaving your car door unlocked in a bad neighborhood so your window doesn't get smashed for the $.36 in the center console. Attacker might take the prize and go without showing that everything around it is just as poorly-built.

  • source
  • parent
  • [–] 8 points 4 months ago (5 children)

    Probably for the same reasons web browsers store them in plain text: They don‘t care.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 18 points 4 months ago (4 children)

    the same reasons web browsers store them in plain text

    Why one web browser stores them in plain text. Fucking Edge.

    Who knows about the others, but I can pretty much guarantee you that Librewolf, for example, isn't doing that shit.

  • source
  • parent
  • hideshow 4 child comments