Perhaps it's cheaper to assume everything leaked or will leak soon.
Perhaps it's cheaper to assume everything leaked or will leak soon.
Thinking of it objectively, almost nobody here can say they would stand for this at any company they worked at or ran. This is not an acceptable IT practice no matter which side of the fence you are currently sitting on - allowing an unvetted entity to modify your internal systems without audit or oversight is completely absurd.
This is what leaves me incredulous about so many people here defending this. I've been on this site daily for how many years I don't know but the one thing that has been consistent is the security idea that an outside entity gaining physical access to your server means that it is irreparably compromised, and that it should be treated as a liability and re-built from the ground up. But somehow it's fine if it's public data in a federal database?