It put yellow sticky notes with username and password on corporate laptops:
The company decided to take some old laptops and give them out to new users. To make life easy for the recipients, they put sticky notes – everyone’s favorite credential-sharing tool – on the laptops with the name of each employee and their initial login credentials on it.Angels and Ministers of Grace defend us. And remember - this was the IT Department that did this.
Let’s just stop for a moment to remark on how bad it is to put usernames and passwords on a piece of paper where the wrong person could see them. Even the IT department should not know your password, should someone in IT themselves turn rogue. So, even if the laptop stayed on a shelf in a closet that only the support staff had access to, having that sticky note would be bad.
However, our situation is even worse because the laptops in question were stored in a conference room while the facilities team finished readying the office for the move. During that time, anyone who had access to the conference room could go in and get multiple user account credentials.
And that's exactly what happened ...
Sigh.
This is why we can't have nice (security) things on the Internet.
6 comments:
Long ago, I worked for a technical projects manager who had trouble using a mouse (on a desk!) and kept calling me because his email disappeared. Each time he had minimized it and didn't know how to restore it. Each time I showed him how to restore it. But the knowledge didn't "stick".
I. Am. Not. Kidding.
There are too many managers who use the term "I know" when they don't know. Participation awardees, I'm sure.
Morons gotta moron.
BTW, loving the book you recommended!
"Even the IT department should not know your password, should someone in IT themselves turn rogue. "
The people who can set and reset your password don't need to know what the current one is. Especially if they already have admin rights to the file system.
Who watches the watchmen?
It's been my experience that most IT "experts" have their job ONLY because they know more than he typical manager/HR hiring drone and thus fool them into thinking they are qualified. And they generally make he situation worse not better.
Sigh... really???
One day came to work (Navy) and couldn't log onto NMCI. It seems I had to go, in person to the NMCI admin and get my new login ID and password. No particular reason, everyone has to do it right now today for no particular reason. It was about then that we learned that China had downloaded 100% of all the files stored at Naval Air Warfare Center China Lake. Thank you EDS, Thank you NMCI. Thank you Big Navy for the One Word to Rule Us and One Word to Destroy Us All.
Post a Comment