As explained, this information should be easily available on any well maintained system to any competent administrator. Your failure to be able to provide this information leads me to believe you are aware of security flaws in your system and are not prepared to reveal them. Our requests line up with the PCI guidelines and both can be met. Strong cryptography only means the passwords must be encrypted while the user is inputting them but then they should be moved to a recoverable format for later use.
Our security auditor is an idiot. How do I give him the information he wants? (Server Fault, 2009)
https://serverfault.com/questions/293217/our-security-auditor-is-an-idiot-how-do-i-give-him-the-information-he-wants
- 44
- 119
Now playing: Mining Melancholy (DKC2).mp3
Jump in the discussion.
No email address required.
Hello I m Prince auditer frm Kenya. Please send all you password now.
Jump in the discussion.
No email address required.
Ok. I will put them here right now:
Account: CARPS_NUMBER_ONE_HATER
Password: F0ckC@rp
Account: I_HATE_EVERYONE
Password: Everyone12
Account: HumanUser123
Password: I4Mhum@n
Jump in the discussion.
No email address required.
More options
Context
More options
Context