Wow. Unbelievable that these companies take security for their prized assets way less seriously than I do. And I have much less at stake comparatively.
Wow. Unbelievable that these companies take security for their prized assets way less seriously than I do. And I have much less at stake comparatively.
> On December 19, 2017 an authorized administrative user's credentials were used by an unauthorized user to log into our Cloud Computing Provider. This unauthorized user created a new administrative user account
They had 6 and a half months to spot this new admin account, and didn't. This is terrible security practice anyway you look at it, and in that context, their statement that "the attacker used an account without MFA" is disingenuous at best.
But indeed, I almost thought this attacker was pretty competent (given the wait until the holiday) until I saw they made a completely new account and left it there for half a year.
A lot of engineering teams unfortunately see strong security as a hurdle to fast development, and/or security is put as a lower priority to feature development or other deadlines. A lot of business units see security as a cost sink and have the "there's only so much we can do to protect ourselves, if they want it they can get it" or "it won't happen to us" mentality.
On the other hand, some companies have security built deeply into their lifecycle, and really care.