Re: The head of information security at TfL had their account hacked
"Oh, it's you? Right away!"
<hang up>
<call him on his listed personal contact number>
"Sorry, we got cut off. You were wanting a password reset?"
700 publicly visible posts • joined 25 Nov 2022
So basically a re-hash/re-vamp of Proxomitron.
Can't beat the security measures I experienced when visiting an air force base - being accompanied by a pair of submachinegun-toting MPs who were quite tech-savvy. This was after my employer had to supply them with both my car registration number and driver's licence number ahead of time, so they could let me through the gate.
The problem here is the corporate environment in general - where nobody knows what the person next to them is doing, let alone what another department has requested/authorised. The rapid turnover of staff in such environments doesn't help either.
"a single actor making 1,300 login requests per minute from a single IP address"
Three strikes in ten minutes and both the account and the IP address get blocked from further attempts for 10-30 minutes, and the activity gets flagged for action.
Repeat performances from the same IP and it gets blocked for an hour, then two, then six, to give admins time to see what's going on.
Standard practice in small organisations (well, at least the ones I overlook), so why not in a multi-$million company?
MFA definitely for data as sensitive and extensive as this.
Is MFA inconvenient for you? Tough cheddar; it's time for you to grow up.
... all of my customers' web sites being pummelled with requests for /autodiscover/autodiscover.xml from all over the world over the past few days.
Of note is the user agent string;
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
No, none of the IPs were Google's.
Because lessons weren't learnt.
I remember the grand old days of the "sort routine wars," when it was universally agreed that the humble bubble sort was to be relegated to the annals of history. And so it was...
Until newer batches of programmers started trickling in, with no knowledge of battles past, and no experience with anything less than an i3 with many gigabytes of RAM.
All it took for MD5 to re-surface was some PFY stumbling across a routine and thinking "gee, this sounds like a good idea!"
"Manager: 'Hey, Dave, you know about AI and stuff, right?'"
Interestingly enough, that's almost precisely how I landed a DBA role a couple of decades ago.
Manager saunters over with a printed sheet of what (from memory) was an SQL stored procedure.
Manager: "Do you know what this is?"
Me: "They're SQL queries."
Manager: "Great! You can take over as the database admin!"
(insert facepalm here)
"Yorick: But I'm an experienced programmer! 'This is the sort of thing you learn on your first day!'"
... I haven't got time to piss around fixing someone else's code; I'll just re-write the whole routine(s) properly and get a 30% size reduction and 50% performance improvement at the same time.
The seller's not necessarily in China. Alibaba is analogous to eBay or Amazon; anyone can sell on the platform, irrespective of their location.
I don't know what's worse though - the fact that the data has been "let loose," or that it was collected in the first place.
"... I wouldn't be surprised if, INA couple if years, majority if such AI would be run locally... "
I'm sorry Dave, I can't let you do that. There's no way the "tech bros" are going to let their cash cow troddle off to greener pastures.
Who still makes spinning rust these days? Did they stick Seagate labels on WD drives or vice-versa?
Fake SSDs and flash memory have been a thing for ages - it's relatively easy to bludgeon the controller to show 2Tb when it's an 8Gb device.
But making HDDs just to re-brand them?