I think you are correct, the question is if the right stakeholders authorized this. You can't break into a 7/11 because some person working there authorized it. Authorization needs to be from all proper stakeholders.
I think you are correct, the question is if the right stakeholders authorized this. You can't break into a 7/11 because some person working there authorized it. Authorization needs to be from all proper stakeholders.
Yes, the two employees could be liable for accepting a request from someone who obviously didn't have the authority to give it. But they wouldn't be the only people liable, and it seems silly to claim that they would be the first people liable.
Why is it that the only two people arrested are those who had the least amount of responsibility and ability to check on the authority of the State department?
That outcome is why the word "pawn" is being thrown around.
Then is it also the fault of the two testers in this case that they too did not verify that all the correct stakeholders were brought in?
It would suck to be in the position of the testers having little or no recourse.
I work in professional services (although not pentesting), so I curious about what would happen to me if I was in a similar position.
IANAL but I've been tracking this pretty closely since I'm also a pentester; everything seems to reasonably indicate that the two guys should be released, but someone else is likely ending up in a court over this.
How?
I can see a situation where the decision to stay or swap off a system is being debated. If one party can send in testers and call out some vulns that might play to their hand.
My initial comment pointed more generally to an example of politics within a company though.