A case study in why credentials are revoked before firings.

    • Echo Dot@feddit.uk
      link
      fedilink
      English
      arrow-up
      15
      ·
      3 hours ago

      Because like all critical infrastructure it was setup by somebody’s kid on work experience

      • IWW4@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        35 minutes ago

        Or some poor guy who is setting it up, because it is a one off and just get it done project, that metastasizes into a fucking mess.

    • WereCat@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      ·
      5 hours ago

      Why not? National Safety Department of Slovak Republic (Narodny Bezpecnostny Urad) had password NBUSK123… just government things

    • betterdeadthanreddit@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      ·
      5 hours ago

      It’s like leaving your car door unlocked in a bad neighborhood so your window doesn’t get smashed for the $.36 in the center console. Attacker might take the prize and go without showing that everything around it is just as poorly-built.

      • OwOarchist@pawb.social
        link
        fedilink
        English
        arrow-up
        10
        ·
        4 hours ago

        the same reasons web browsers store them in plain text

        Why one web browser stores them in plain text. Fucking Edge.

        Who knows about the others, but I can pretty much guarantee you that Librewolf, for example, isn’t doing that shit.

        • VeganCheesecake@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          4
          ·
          4 hours ago

          If you can autofill passwords without authenticating in some way, they are probably either stored in plaintext, or encrypted with a key that is stored in plaintext. Cause, like, how is it supposed to magically encrypt it.

        • Reuben@lemmy.nz
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 hours ago

          I believe Firefox (and forks) only encrypt if you have set a master password.