OWASP Data Breach Notification
owasp.org
owasp.org
Yes, they should have updated their config, but why did you need a resume full of private info to join, and why did you not delete it after the membership is approved (let alone keeping it for decades).
What...of all organisations who should know this to be completely untrue. You cannot guarantee that breached data has been removed from the Internet.
I cannot understand why they didnt say "removed from our servers" rather than "removed from the internet" though, seems almost intentionally misleading.
The data is on servers "not on the Internet"?
Edit: the "disable indexing" makes it sound like there was some sort of system to upload private stuff and the directory it went in had mod_index enabled. Which i guess would not have much to do with MediaWiki.
GET /file.name
ERROR 404
[User: wtf is going on]
Turns on directory index
Sees /filé.name
[Oh that's the problem]
Forgets to turn directory index off
My firm have a Nessus scanner and we point it at ourselves as well as our customers. There are also several checks on the monitoring system that will flag if something suddenly starts working.
Background radiation is about right.
Run up a honeypot VM with a web service on it and watch the logs with something like lnav. You soon get a feel for how fast the legitimate (and I use that term advisedly) crawlers like Google and that rock up along with the others.
You will see a lot of hits from things with a Github link within their agent header - script kiddies or perhaps clever kiddies pretending to be script kiddies - more analysis needed. You will also see hits from agents claiming to be Google or Bing or Firefox on Commodore 64. Again, careful packet analysis, IP lists etc can be instructive ... if you can be arsed.
Anyway.
Humans cannot see network traffic. When you instruct your firewall to do something via its GUI or CLI you are merely providing instructions that may or may not actually do anything. Do feel free to actually test it. nmap, for example, is available for port testing and much, much more.
Newsflash: humans make mistakes all the time.
You can see why everyone would then start pointing fingers at each other. Hopefully, regular reviews and careful analysis prevent this kind of situation.
The best solution to keeping the combinatorics down is to have someone with authority who is happy to say “no” when a proposed new service doesn’t closely align with the org’s key goals.
Without incentives it will just keep happening. We need to:
1. Incentivize emphasis on security by penalizing data breeches in a non-trivial way
2. Make orgs much more careful about the data they collect by mandating penalties which scale exponentially with the potential harm of the data which was released -- up to and including existential destruction
For one obvious, simple example, most tech is optimized for "Make it easy to access all data from anywhere" as opposed to "require affirmative consent for connections to all new locations". It is surprisingly difficult to lockdown most systems, whether they be laptops or server networks, with that easy rule. Just look at folks who use Little Snitch - it can be difficult to use this effectively because so many apps need to talk to so many different servers that it can just be exhausting attempting to determine if a new connection is malicious or not.
Similarly, look at some recommended settings for a "secure" Content Security Policy on the web. There are a boatload of different options that are recommended to be set, because the original defaults (e.g. "Sure, you can load me in an iframe of any other site!") are so insecure.
As a consequence of this, it's very difficult for any (a) organization that can't afford top-notch security folks or (b) organizations that are so large, with a potentially huge history of acquisitions over time, with a giant surface area where all you need is one "chink in the armor", to prevent breaches.
> OWASP collected resumes as part of the early membership process, whereby members were required in the 2006 to 2014 era to show a connection to the OWASP community. OWASP no longer collects resumes as part of the membership process.
Why did OWASP retain this information ten years after they stopped the practice?
Good reminder why not to collect and keep personal data you don’t need