
Sign up to save your podcasts
Or
Episode F -- Aboot that
it's not a boot, it's just a really big shoe
Matt won’t be joining us tonight, it’s Ben’s fault. A quick shout out to Jimmy Vo, you will need approximately 15 or F shot glasses for this episode.
Aboot, Aboot, Aboot, Aboot!
And tonight, let us regale you with tales of:
And if you've got commentary, please sent it to [email protected] for us to check out.
DISCLAIMER: It's not that explicit, but you may want to use headphones if you're at work.
ADDITIONAL DISCLAIMER: In case it is unclear, this is the story of 4 opinionated infosec pros who have sufficient opinions of their own they don't need to speak for anyone except themselves. Ok? Good.
In this episode:
There is this website where I noticed that they display your login details after offering a quote in plaintext, ie. they display your username and a password on a http:// connection. So I called their call center and spoke with the manager, yeah, she will relay that information (but I kinda got the impression that she didn't understand what the problem is). Nothing happens for weeks. After maybe 2 months I go back to check and here you go, my username with password are still shown in plaintext on the site. So I sent them an email, clearly marked "to IT or IT security something" explaining it a little bit more technical. Nothing happens again. Since I raised the original issue, about 4 months have passed.
The question is now - is it worth pursuing this further?
Cheers
T
PS: Should anyone of you guys be once in London, pls ping me and I buy you a beer! Or two?
Creative Commons license: BY-NC-SA
4.8
1313 ratings
Episode F -- Aboot that
it's not a boot, it's just a really big shoe
Matt won’t be joining us tonight, it’s Ben’s fault. A quick shout out to Jimmy Vo, you will need approximately 15 or F shot glasses for this episode.
Aboot, Aboot, Aboot, Aboot!
And tonight, let us regale you with tales of:
And if you've got commentary, please sent it to [email protected] for us to check out.
DISCLAIMER: It's not that explicit, but you may want to use headphones if you're at work.
ADDITIONAL DISCLAIMER: In case it is unclear, this is the story of 4 opinionated infosec pros who have sufficient opinions of their own they don't need to speak for anyone except themselves. Ok? Good.
In this episode:
There is this website where I noticed that they display your login details after offering a quote in plaintext, ie. they display your username and a password on a http:// connection. So I called their call center and spoke with the manager, yeah, she will relay that information (but I kinda got the impression that she didn't understand what the problem is). Nothing happens for weeks. After maybe 2 months I go back to check and here you go, my username with password are still shown in plaintext on the site. So I sent them an email, clearly marked "to IT or IT security something" explaining it a little bit more technical. Nothing happens again. Since I raised the original issue, about 4 months have passed.
The question is now - is it worth pursuing this further?
Cheers
T
PS: Should anyone of you guys be once in London, pls ping me and I buy you a beer! Or two?
Creative Commons license: BY-NC-SA