A case study in why credentials are revoked before firings.

    • WereCat@lemmy.world
      link
      fedilink
      English
      arrow-up
      40
      ·
      15 days ago

      Why not? National Safety Department of Slovak Republic (Narodny Bezpecnostny Urad) had password NBUSK123… just government things

    • Echo Dot@feddit.uk
      link
      fedilink
      English
      arrow-up
      30
      ·
      15 days ago

      Because like all critical infrastructure it was setup by somebody’s kid on work experience

      • IWW4@lemmy.zip
        link
        fedilink
        English
        arrow-up
        8
        ·
        15 days ago

        Or some poor guy who is setting it up, because it is a one off and just get it done project, that metastasizes into a fucking mess.

            • Corkyskog@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              14 days ago

              That’s only usually true, but heavily depends on category. If someone is offering some service like software or managing employee benefits it can often be outweighed by other factors.

    • betterdeadthanreddit@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      arrow-down
      1
      ·
      15 days ago

      It’s like leaving your car door unlocked in a bad neighborhood so your window doesn’t get smashed for the $.36 in the center console. Attacker might take the prize and go without showing that everything around it is just as poorly-built.

    • JeeBaiChow@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      15 days ago

      Well how else would they help the users if they ever forgot their passwords? Duh.

      /s

    • CosmoNova@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      15 days ago

      Probably for the same reasons web browsers store them in plain text: They don‘t care.

      • OwOarchist@pawb.social
        link
        fedilink
        English
        arrow-up
        13
        arrow-down
        1
        ·
        15 days ago

        the same reasons web browsers store them in plain text

        Why one web browser stores them in plain text. Fucking Edge.

        Who knows about the others, but I can pretty much guarantee you that Librewolf, for example, isn’t doing that shit.

        • VeganCheesecake@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          9
          ·
          15 days ago

          If you can autofill passwords without authenticating in some way, they are probably either stored in plaintext, or encrypted with a key that is stored in plaintext. Cause, like, how is it supposed to magically encrypt it.

        • CosmoNova@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          15 days ago

          Firefox and chromium browsers also store them in plain text. I know because I literally copied them from a file when setting up my password manager.