• Optional@lemmy.world
    link
    fedilink
    arrow-up
    21
    ·
    5 hours ago

    IT: We need a full audit, a department of people to run patches and tests, and everyone gets off of Windows immediately.

    Director: Well we can’t hire anyone but if you want we’ll let you upgrade everyone’s system to Windows 11. They’ll probably be mad about it, but it’s all we can do right now. Hey it’s got AI now! You like that, right?

    Rinse/repeat.

  • Frezik@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    22
    arrow-down
    1
    ·
    6 hours ago

    As a quick test, I asked my wife to guess their password. They’re technically minded but not an IT expert.

    They got it on the third try. First two were “Password” and “Abc123”, which are not bad guesses, either.

    • SaveTheTuaHawk@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      3 hours ago

      when you have two hour breaks for lunch and kiss everyone like you haven’t seen them in 30 years, ya got no time pour le password.

      Trump’s nuclear football code was 0-0-0-0.

    • Frezik@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      14
      ·
      6 hours ago

      Not quite that, but it was basically a test of “you can do anything if you wear a hi-vis vest and a hard hat”.

      • BarneyPiccolo@lemmy.today
        link
        fedilink
        arrow-up
        4
        ·
        3 hours ago

        An embroidered logo polo shirt, khakis, a lanyard with a laminated pass, and a clipboard can get you pretty far. Get one of those plastic ones that open up to hold papers, and put some stickers on it, then tear the corners off a couple. Carry a clicky pen, and click it a lot. Have a fresh haircut. Nobody wants to talk to that guy.

    • Komodo Rodeo@lemmy.world
      link
      fedilink
      arrow-up
      28
      arrow-down
      1
      ·
      8 hours ago

      distracts French guards by surreptitiously dropping wheel of cheese and pack of cigarettes on floor

      • nocturne@slrpnk.net
        link
        fedilink
        arrow-up
        23
        ·
        8 hours ago

        I heard one of the thieves mispronounced croissant and it distracted all of the guards so the rest of the team could do the heist.

        • StinkyFingerItchyBum@lemmy.ca
          link
          fedilink
          English
          arrow-up
          7
          ·
          edit-2
          3 hours ago

          I heard the thieves strategically placed an American snack platter with grapes, cheese, crackers and cold cuts with a sign that read “Charcuterie” and all the guards called for backup to correct the senseless offenders.

          • SaveTheTuaHawk@lemmy.ca
            link
            fedilink
            English
            arrow-up
            2
            ·
            3 hours ago

            “…I unclog my nose in your direction, sons of a window-dresser! So, you think you could out-clever us French folk with your silly, knees-bent, running about, advancing behavior! I’ll wave my private parts at your aunties you… cheesy leather, second-hand, electric donkey bottom biters!”

            I burst my pimples at you and call your door-opening request a silly ting! You… tiny-brained wipers of other people’s bottoms!"

  • Auli@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    ·
    5 hours ago

    I can confidently say this is more common then you would realize.

  • Komodo Rodeo@lemmy.world
    link
    fedilink
    arrow-up
    17
    arrow-down
    1
    ·
    edit-2
    7 hours ago

    Speaking as someone who’s worked contracts in secure facilities, I can say from experience that no one working in a place like this is even mildly surprised. The extent to which ‘learned blindness’ is applied should worry people still assuming that vaunted organizations or even government facilities are protected by strong security policies instead of mostly by the base restriction of non-authorized personnel from work areas.

    Not naming names, but if your org doesn’t use the classic Admin & Password defaults, and forces you to renew your terminal passwords on a regular basis, don’t write it down on a Post It and stick it to your fucking monitor where anyone walking past can see. The sheer scale of the incompetence here is galling, in that teenagers have a better sense for passwords than the Louvre security & tech team apparently.

    Edit: spaced and omitted part of sentence structure

    • FooBarrington@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      7 hours ago

      Not naming names, but if your org doesn’t use the classic Admin & Password defaults, and forces you to renew your terminal passwords on a regular basis, don’t write it down on a Post It and stick it to your fucking monitor where anyone walking past can see.

      Got it. I’ll write it down on a Post It, take a photo, and will make that my desktop background instead.

    • CubitOom@infosec.pub
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      2
      ·
      9 hours ago

      Classic mistake, what you do is create a Python script that will search the internet for art Museums in Paris, then you parse them to compile a list and then try them each one by one.

    • StinkyFingerItchyBum@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      6 hours ago

      L.u.v.e.r - access denied - “shit”

      L.o.u.v.i.r. - access denied - " shit shit"

      L.a.u.p.e.r - access denied - you have three attempts remaining -“Oh mon shiiiiit!”

      ****** - access denied - shiiiiit

      H.u.n.t.e.r.2 - access denied - holy shiit!

      O.v.e.r.r.i.d.e - administrator access granted.

  • celeste@kbin.earth
    link
    fedilink
    arrow-up
    6
    arrow-down
    1
    ·
    8 hours ago

    Mentioned this to my elderly father and he said “I could do better than that.” He’s a master of security compared to that.