Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Oh, to be fair I should mention that it was an internal system. External threat actors were not a major concern.

Preaching to the choir, but that's simple black and white thinking. Once an attacker has gotten in, it's better if at least there's less damage they can do. The more damage an insider could do, the more damage an outsider who social engineers some credentials can do.



I understand defense in depth. I'm just mentioning it because is incalculable worse if those pages were exposed externally since any script kiddie would be able to pwn the site immediately.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: