"Well, what if your infrastructure gets breached and everyone’s password is published in plaintext to the whole wide world?"
"What if this doesn't happen because our security is amazingly good? ^Käthe"
This is begging for it.
"What if this doesn't happen because our security is amazingly good? ^Käthe"
This is begging for it.
What’s often lacking though is a clear path for reporting security issues to people such as this representative. They don’t have a process to flag something for the security team.
And doubling down as well, that’s a bold strategy.
I know, and it ain’t fucking pretty. Plaintext passwords (and stupid customer service) are just the tip of the iceberg.
Telcos are right up there with internet-connected industrial control systems when it comes to security and the huge fallouts of a breach.
[1] https://twitter.com/fabricio_giglio/status/98236273592413798...