Our security auditor is an idiot. How do I give him the information he wants?
serverfault.com
serverfault.com
Asking for everything might sound more legitimate than asking for one small thing. Perps generally go with their gut. In this case, this "auditor" shot for the moon with the wrong mark.
In fact, this seems like a more effective way to sniff out plaintext password storage than saying "show me everywhere you touch passwords and how they're encrypted".
One of the more interesting government audits I have heard about was the auditor did a basic internal audit and said he was part of physical secuity ect so people knew he was part of the audit team. He then showed up late, turning off the power supply to the building and then pointing at people who show up at the generator and saying "bang your dead" this is part of an audit etc. If they failed to call security before everyone was "dead" they where considered to have failed that part of the audit. He also attempted to get into the building without showing up on camera's ect. All of which sounds like a fun job and a good idea.
It's a private key after all.
Maybe the poster is writing a book on cracking systems? Who knows. But it smells like a hoax.
What purpose would faking 6 months of inbound traffic serve? If he just wanted to cover his tracks, wouldn't he just erase logs rather than trying to make them look legit? That would seem like doing things the hard way.
*The "new security policies" were introduced two weeks
before our audit, and the six months historical logging
was not required before the policy changes.
These "policies" were introduced by whom? His payment processor or by his company on the advice of this "auditor"?
Or did the OP make this up? In short, I need;
A way to 'fake' six months worth of password changes
and make it look valid
A way to 'fake' six months of inbound file transfers
Why is the poster requesting help generating plausible fake data? Is he naive? Afraid of losing his job? Unaware of the legal implications?Of course, quitting is the other out, but I do think he has a moral obligation to prevent his company from handing any of this information over to the auditor.
- what this guy is asking for
- how that is in violation of the PCI data security standard
- explain that you are not able, and not allowed to provide this information
- explain that this likely means the auditor is a hack and steps need to be taken to get a proper auditor
To quote: if I don't provide this information we loose access to our payments platform
He did manage to start a very popular thread, and get a ton of people with really high rep to respond AND get a link on HN. He just threw out some bait, and the community swarmed like starving fish.
This is true of all "light" SO/SF posts. Nobody gets excited about answering someone's obscure apt-get question. Everyone gets excited when they can spend their boring workday telling some dude that his security consultant is fucking him. It's the same reason people read "People Magazine" instead of "Purely Functional Data Structures".
The modern currency for trolls is "lulz".
The "social engineering" idea is definitely worth considering, and the poster definitely needs to run this up the flag pole to his senior management. Preferably, this email would also have the words "contact our legal counsel" prominently displayed.
It's still a troll.