You can't make this up. EY screwed up, but they could not have reasonably assumed that someone sets up a fake bank branch.
You can't make this up. EY screwed up, but they could not have reasonably assumed that someone sets up a fake bank branch.
https://newsinfo.inquirer.net/1441886/ex-dotr-exec-others-fa...
“The NBI said Arellano, an employee at the BPI branch in Malate, Manila, had admitted to receiving P10 million for issuing bogus bank certification documents that Tolentino and his law office needed as the supposed local trustee of Wirecard.”
I guess it goes to show that if you are dealing with enough cash to bribe third world governments then all kinds of new fraud schemes become possible.
We shouldn't discount the connections a GRU agent would have in 3rd world govs, they know who is corrupt enough (or able to be coerced) to do their bidding. Fake banks accounts is pretty old stuff in the spying world. It's not just money.
As the responsible manager for IT (usually CTO - internal SOX was a different matter) I have been "asked" by EY (and KPMG) about IT setups and security several times for audits. And I could have told them whatever I like, the people were right out of university with no clue about the matter and in no position to ask the right questions except reading their checklist; I always had the impression they only knew half the words they were reading.
[Not the person you replied to.]
Did the person you replied to work for LinkedIn? What's the context for this question?
I misread this as "reponsible manager for IT [at Wirecard]", hence the question.
Do you have any programming skills? ... No? Then no. Then they started blabbing about what the data could be and it basically came down on them not understanding what random is and they then just checked it off and went on. Since then I do not believe any audit which come from those paper farms.
“Kinder prüfen meine Gesellschaft”
children check my company
„Kommen, prüfen, meckern, gehen“
come, check, complain, go
KPMG seems to have quite a reputation.
Though that reading is a bit weird, it's practical enough to tickle the funny.
When someone asks a question like this, they're not literally asking you to show them it.
They just want an expert to confirm it they could show it, so they can check off their box for due diligence.
Congratulations. You were the expert.
"Can you show it's actually encrypted?"
Yes, we ensure that the data is only available via TLS foo.bar with encryption algorithm baz, which is on the approved list. We have monitoring and logging that ensure that we receive an alert if the port the app is on is not encrypted, and if you'd like we can dump the traffic to show you that there is no clear text available.
Further, only users on the approved admin list can make a change or deploy to production, or login to the server as root. Moreover, we do a background check on employment for all users who have admin access, and all deployments and code changes require at least one other employee to approve them, and we log who they were, and what the change was.
But them knowing what they are checking, is maybe a reasonable ask?
Well, what is the purpose of an auditor then in this context? Genuine question. Not my world.
I know code auditors - and they have to know about programming and the domain to provide any meaningful audit.
In this context, they're just making sure the answer isn't "no, it's not encrypted". Sure, you can lie, and that would fool them. But your answer will be cross-checked with other employees, maybe with other documentation if those exists.
And sure, you can forge all of those as well, as Marsalek did with his bank statements. But these sort of verification significantly raises the bar to how difficult it is to commit fraud: you now need to get several people into the conspiracy to forge those documents and audit trail. Your average employee isn't willing to lie for their company for no good reason and risk prosecution, and may very well whistle-blow on you.
Software development has a frustrating history of reappropriating words from other contexts. Your "code auditor" is probably more akin to an OSHA compliance officer/safety inspector. Again, experience helps, but you don't need to be the architect of the Pyramids to ensure everyone onsite is wearing a helmet.
They make a good-faith effort to ensure some checklist of conditions are met.
A billion dollars can buy a lot of grift.
But I guess bean counters aren't the demographic for heist or confidence movies so maybe the Hollywood ending didn't occur to them.