Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Mark Wyner Won’t Comply :vm:
@markwyner@mas.to  ·  activity timestamp 6 days ago

The museum Louvre in France was recently the victim of a heist worth over €88 million. In broad daylight.

A previous security audit revealed the following weaknesses with their security system:

1. Their password was “louvre”
2. Their security system was running on Windows 2000

Ouch.

https://www.tomshardware.com/tech-industry/cyber-security/louvre-heist-reveals-glaring-security-weaknesses-previous-reports-say-museum-used-louvre-as-password-for-its-video-surveillance-still-has-workstations-with-windows-2000

#Louvre #France #Heist #Museum #OpSec #Security #Password123

  • Copy link
  • Flag this post
  • Block
diesch
@diesch@loma.ml replied  ·  activity timestamp 6 days ago
@markwyner it wasn't a "resulting security audit" but an audit from 2014.
  • Copy link
  • Flag this comment
  • Block
Bebadefabo
@bebadefabo@mastodon.social replied  ·  activity timestamp 6 days ago

@markwyner many major retail companies here in the US are still running on XP.

  • Copy link
  • Flag this comment
  • Block
Mark Wyner Won’t Comply :vm:
@markwyner@mas.to replied  ·  activity timestamp 6 days ago

@bebadefabo this would not surprise me. I don’t think many folks take security seriously. It’s like batteries in smoke alarms.

  • Copy link
  • Flag this comment
  • Block
Bebadefabo
@bebadefabo@mastodon.social replied  ·  activity timestamp 6 days ago

@markwyner I was an IT engineer for the one with the big yellow tag for many years. The short term calculus on costs versus benefit ALWAYS overran the conversation. They will not change the system until it is exploited and used against them in a very public way.

Even basic PCI compliance is smoke and mirrors when your system is built on an infrastructure that's full of holes. Not a single one of these retailers should be allowed to process customer data or credit cards. Security is a joke

  • Copy link
  • Flag this comment
  • Block
Alexandre Mazari
@scaroo@floss.social replied  ·  activity timestamp 6 days ago

@markwyner Both of those stories date back to 2014 according to the French press. Can't guarantee their security practices changed in the meantime tho :)

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login