Unable to load image

Our security auditor is an idiot. How do I give him the information he wants? (Server Fault, 2009)

https://serverfault.com/questions/293217/our-security-auditor-is-an-idiot-how-do-i-give-him-the-information-he-wants

As explained, this information should be easily available on any well maintained system to any competent administrator. Your failure to be able to provide this information leads me to believe you are aware of security flaws in your system and are not prepared to reveal them. Our requests line up with the PCI guidelines and both can be met. Strong cryptography only means the passwords must be encrypted while the user is inputting them but then they should be moved to a recoverable format for later use.

:marseyxd#:

119
Jump in the discussion.

No email address required.

I remember the good old days when clicking the forgot your password link would just have them email you your password.

Jump in the discussion.

No email address required.

When I was young, I got asked to implement that at my first professional job, and I had to explain to the boss why it's a good thing that isn't possible.

Jump in the discussion.

No email address required.

That is insecure. You should just type in your email address and get told your new password is now abc123

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.