Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How could a stolen session token even be useful. I have to log into tools every day, if I change IPs at all I have to re-authenticate, and all prod access needs to be approved and has a finite lifespan.

How could a CI company be that negligent. They should be leading this stuff from a best practice point of view.



The employee had malware on his computer, and the hackers might've used a VPN that's located in a "safe" zone.

Security is pretty lax at most companies, and the more employees you have, the worse it is.


No need for a VPN if you have access to the laptop, you just use that as a proxy. Look at any c2, open source or commercial, and they'll have that as a feature.


Most places I’ve worked, has the concepts from above.

Security is lax at most companies but even having worked as an engineer on support rotation, customer anc production access was the last thing I could do and I needed to have exhausted all other options. I don’t feel retaining production access to generate tokens should be a thing.


It depends on the eng. If you're a senior eng with on-call responsibilities, you're getting full time prod access.


Hard agree. A stolen token was still valid a week later! There is no excuse.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: