Reply to post: Design Strategy: What if the data becomes public?

Not very Suprema: Biometric access biz bares 27 million records and plaintext admin creds

TonyJewell

Design Strategy: What if the data becomes public?

Putting aside the issues that made this data accessible to the two researchers, to me, the most unforgivable thing is storing people's passwords and biometric data as non-hashed.

So often now, products come to market as experimental internal proof of concepts that are then productionised and rushed to market. If you are transporting and storing such sensitive data you should start your design with the question: what if the data leaks - how can I minimise the risk? The evidence appears to be growing that this is rarely done.

Further, before go live any such system should be fully audited for security.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon