Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can't help but feel there is some kind of social experiment going on here.

I mean I know there are a lot of incompetent people out there, but a security auditor asking for a list of plaintext passwords is not something that should take more than an email or two to resolve even in Bizarro world. "Techies" exhibiting this kind of willful ignorance are usually a bit better and hiding under their rock.



I take it you've never worked with someone who was truly incompetent. Often such people have some sort of defense mechanism that allows them to cover up their incompetence with some degree of effectiveness. But sometimes it shines right through, and then you end up gobsmacked that it's even possible for someone to be that ignorant/illogical.

But it does happen, I've seen it too many times.


Sure, but such people can not remain the lynchpin of a PCI auditing operation. I mean how many WTFs from anyone who has half a clue have to be sent to the brass at this company and the ones they are auditing on behalf of before someone thinks "holy shit our entire reputation and business is being flushed down the toiler on a daily basis?"

It just doesn't pass the smell test for me. I don't know what it is, but something is missing from this story.


Maybe not forever, but long enough to cause pain in your life? Sure. Perhaps the company was bought or created by someone with too much money and not much domain expertise and then they gave their incompetent relative a position without much oversight. Wouldn't be the first or last time that happened.


Yes, but if your payment gateway is going to shut you off based on this nonsense you call them up and explain the situation to them and then they investigate. There are too many parties involved for this kind of willful ignorance to be the last word.

I dunno, maybe it's true, but for me the story still isn't adding up.


He'd be a good actor, because he clearly doesn't know what PCI compliance is. He mentions PCI should be installed.


I also really feel this guy is trying to get the password by social engineering means or something it just seems completely ridiculous to ask for this stuff. Why would he need the info in the first place? I wished the author of the post had asked him that. I'd like to know his answer to that.


I can tell you what it is, he's got some requirement he needs to fulfill (like, say, ensuring password strength) and he's figured out some way to satisfy it by analyzing all of the plain-text passwords. He refuses to give his reasons and refuses to back down because those are parts of the personality flaws which have led him down this road to start with. People who never accept they are wrong, never accept criticism, and never give up on bad ideas: those are the people who hold on to bad ideas forever. How do you think incompetence is maintained in the face of a world filled with people hostile to it? It takes a strong defense mechanism.


People are naturally unresponsive to criticism. If you can get someone to admit they're wrong without shame or guilt, they will happily concede.


Social engineering was my initial suspicion as well. However, that really doesn't fit with the auditor's obstinate response. At this point an intelligent auditor should be coming clean so that this doesn't go public (and so that his company doesn't lose the contract and get further heat).

I have the same concern you do that he shouldn't need this information. Reading some of the other comments here, though, leads me to believe that there really are people who feel like this is "security". I've definitely encountered sites and password systems that require you choose drastically different passwords from any you've chosen in the past. This may be what the auditor was getting at (though in my opinion it's a weak, even counter-productive security measure)


Some programmer in AZ told me a couple days ago to in order to search their user profile database(location, department etc), instead of changing his web service to accept some criteria, I should just use the GetAll() method and do it locally (a few thousand profiles), when presented with the logical use cases and the little "performance issue" he quit his job.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: