Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social  ·  activity timestamp 3 weeks ago

And this, kids, is why we never ever set up easy-to-guess passwords. Even in testing, even temporarily. Just pwgen it, every time.

https://www.unionesarda.it/en/world/louvre-robbery-security-flaws-the-obviously-password-was-quot-louvrequot-ft1kkp6c

> accessing the museum's video surveillance server required typing the all-too-obvious word: LOUVRE

#InfoSec

  • Copy link
  • Flag this post
  • Block
AccordionBruce
@AccordionBruce@mastodon.social replied  ·  activity timestamp 2 weeks ago

@rysiek @ShaulaEvans
The MuseumIsNotThePassword would be a solid password

  • Copy link
  • Flag this comment
  • Block
freediverx
@freediverx@mastodon.social replied  ·  activity timestamp 2 weeks ago

@rysiek
Museum officials acknowledged the oversight and swiftly changed to a more secure password (LOUVRE2).

  • Copy link
  • Flag this comment
  • Block
Fallon, knitting, perma-tired
@fallonturing@disabled.social replied  ·  activity timestamp 2 weeks ago

@rysiek lmaoooo no fucking way! With that security, they deserved to get robbed hahahhahahahaha

  • Copy link
  • Flag this comment
  • Block
Agitatra 🚲🐻🌿🇪🇺🇺🇦
@agitatra@berlin.social replied  ·  activity timestamp 2 weeks ago

@rysiek And this, kids, is why we don't trust sensational news from an obscure Italian magazine in English.
Yes, in 2014 a security audit revealed significant flaws in the Louvre cyber-security, including the usage of: "LOUVRE" as a password.
No, we don't know what the current passwords are and which flaws have been adressed in the past eleven years. So we stay alert but don't hawk about such allegations as truth.

https://dailycaller.com/2025/11/03/louvre-password-security-system-heist/

  • Copy link
  • Flag this comment
  • Block
Furbland's Very Cool Mastodon™
@GroupNebula563@mastodon.social replied  ·  activity timestamp 2 weeks ago

@rysiek they should’ve made it “hunter2”.

  • Copy link
  • Flag this comment
  • Block
💡𝚂𝗆𝖺𝗋𝗍𝗆𝖺𝗇 𝙰𝗉𝗉𝗌📱
@SmartmanApps@dotnet.social replied  ·  activity timestamp 2 weeks ago

@rysiek
https://dotnet.social/@SmartmanApps/110891046754669701

  • Copy link
  • Flag this comment
  • Block
Baltergeist
@Cotopaxi@mstdn.social replied  ·  activity timestamp 3 weeks ago

@rysiek
Is this for real..? 😵‍💫🤯😱

  • Copy link
  • Flag this comment
  • Block
Tuckers Nuts Resist! 🇺🇦 
@jstatepost@mstdn.social replied  ·  activity timestamp 3 weeks ago

@rysiek
How do you say, "Sacré bleu," in French?

  • Copy link
  • Flag this comment
  • Block
Lorry
@lorry@infosec.exchange replied  ·  activity timestamp 3 weeks ago

@rysiek I kinda love the French for this though. Either all those years of encryption being a criminal offence, or just the French stereotype of generally not giving a fuck about anything, led to this.

And as a Brit, I can't laugh. The last time somebody stole the English Crown Jewels, he lost them forever in a swamp.

  • Copy link
  • Flag this comment
  • Block
SuperMoosie
@SuperMoosie@mastodon.au replied  ·  activity timestamp 3 weeks ago

@rysiek

Mate has recently been installing security cameras for the Army on the front gates of bases.

He asked what passwords they would like to use for their system.

Their replies for suggested passwords were easier to guess

  • Copy link
  • Flag this comment
  • Block
Quercus 🟡⚪🟣⚫
@coppercrush@beige.party replied  ·  activity timestamp 3 weeks ago

@rysiek Most of us had better security protocols as a 10 year olds than the Louvre. And we wonder why everything is shit - morons are running the world. Good for those thieves.

  • Copy link
  • Flag this comment
  • Block
Judgy Gigi
@JudgyGigi@mstdn.plus replied  ·  activity timestamp 3 weeks ago

@rysiek they…they changed the password right - it’s been 10 years.

  • Copy link
  • Flag this comment
  • Block
Number6 :syncthing:
@number6@fosstodon.org replied  ·  activity timestamp 3 weeks ago

@rysiek

But that didn't have anything to do with the robbery, right?

Also that password was from 2014, applied only to the surveillance software, and for all we know was changed in the interim.

What's amazing is how much authority you have just by putting on a yellow vest.

  • Copy link
  • Flag this comment
  • Block
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social replied  ·  activity timestamp 3 weeks ago

@number6 oh yeah, the yellow invisibility vest is totally a thing

  • Copy link
  • Flag this comment
  • Block
zombiecide
@zombiecide@polyglot.city replied  ·  activity timestamp 3 weeks ago

@rysiek oh god I though that was a dad joke

  • Copy link
  • Flag this comment
  • Block
Anthropy
@anthropy@mastodon.derg.nz replied  ·  activity timestamp 3 weeks ago

@rysiek 😬 .. 😩 .. 😭 .... why are people like this 😭😭😭

oh my fuck we really need to make third party auditing a mandatory requirement for everything that has an internet-facing IP

  • Copy link
  • Flag this comment
  • Block
AlexTECPlayz
@alextecplayz@techhub.social replied  ·  activity timestamp 3 weeks ago

@rysiek ...good lord.

  • Copy link
  • Flag this comment
  • Block
Like Mucas :pumpkin_laugh:
@mwl@io.mwl.io replied  ·  activity timestamp 3 weeks ago

@rysiek heck, if I'd discovered that, I would have felt morally compelled to steal those jewels! flan_mask COMPELLED, I say!

  • Copy link
  • Flag this comment
  • Block
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social replied  ·  activity timestamp 3 weeks ago

@mwl that password IS the jewel

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login