• just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 year ago

    Not just that, but devices as well. First rule in Black Hat is keeping your mouth shut when you find an exploit. With practically everyone now having phones on them 24/7, or insecure internet connected devices at home, the attack surface area is everywhere. Almost a guarantee that government employees are targeted specifically for attack, and a large number are, or have been compromised at some point.

    The only way to help prevent such things is force government employees to abide by specific security practices for devices, which is practically impossible.

    • Turkey_Titty_city@kbin.social
      link
      fedilink
      arrow-up
      5
      ·
      edit-2
      1 year ago

      I work for a small medical firm nobody has ever heard of. Almost all our employees are targeted within a week of hiring on their personal devices with spearfishing trying to get company creds. It’s insane.

      • ooboontoo@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        1 year ago

        It sounds like they have real-time access to the company directory. Might want to review the logs of accounts with permissions and access to your domain controller.

        • foggy@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          1 year ago

          Lmao right?! This happened at a company I worked for very briefly. They… were storing their ssl cert on an ftp server… And that’s just the shortest, most damning sentence I can think of to describe how unsecure the whole operation was. They also had govt contracts, so yeah, pwnd.

          • LrdThndr@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            1 year ago

            I posted about this a while back on that other double-d site, but I used to be an outsourced it guy for a bunch of companies.

            One of my clients was a small local collection agency. Their network was aged and falling apart, we we sold them a full network update - new server, new infra, new computers. They even ordered the newest version of their agency software.

            We got it all set up in parallel to the existing setup, and were at the point of installing the server app, but for the life of me, I couldn’t get the damned thing to work.

            So I called support and told them the issue. The support guy said “Oh, yeah. That’s a known issue. You just need to make anybody who needs to use the software a domain admin, and you have to leave the admin panel on the server app logged in at all times with the screen unlocked.”

            I sat in stunned silence for a few seconds contemplating what this idiot just told me.

            “If that’s a requirement to run this software, then go ahead and transfer me to whoever I need to talk to to get a refund on this, because you’ve got to me out of your fucking mind. There’s not a chance in hell I’m going to do that on a server that handles peoples’ financial data.”

            He stammered for a minute then transferred me to someone who apparently had seen a computer before, and they were able to fix the issue — a cache directory just needed write permission.

            But the part that bothers me is… how many other people did he tell that to and they just blindly followed those directions? If I had told the manager or owner they needed to call, they would have just done it with no reservation.

            In small orgs with no IT, where the tech stuff is just done by a nephew or a staffer that’s “good with computers,” there’s zero thought given to security. I’d seen it with dozens of small companies - they’d done their own IT work forever, and had just called me in to address a thorny problem, and I find that their database is open to the world, or their whole org runs off an access database file sitting on an XP home edition computer somebody brought in.

            It’s fucking terrifying.