POV-Ray : Newsgroups : povray.off-topic : I don't know what's worse ... Server Time
1 May 2024 16:18:26 EDT (-0400)
  I don't know what's worse ... (Message 1 to 10 of 149)  
Goto Latest 10 Messages Next 10 Messages >>>
From: Mike Raiford
Subject: I don't know what's worse ...
Date: 30 Apr 2008 11:52:24
Message: <481895b8$1@news.povray.org>
... that someone pulled a power cord for only $10, or that the "Super 
hacker" is a fraud ...

http://thedailywtf.com/Articles/The-Super-Hacker.aspx


Post a reply to this message

From: Kyle
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 12:41:24
Message: <nv7h1418mk4v8qsurdiup3rdsiugon5n77@4ax.com>
On Wed, 30 Apr 2008 10:46:00 -0500, Mike Raiford <mra### [at] hotmailcom> wrote:

>... that someone pulled a power cord for only $10, or that the "Super 
>hacker" is a fraud ...
>

It sounds like he found a valid vulnerability to me.  Physically securing the hardware
is kind of important too.


Post a reply to this message

From: Mike Raiford
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 13:05:09
Message: <4818a6c5$1@news.povray.org>
Kyle wrote:

> 
> It sounds like he found a valid vulnerability to me.  Physically securing the
hardware is kind of important too.
> 

Security hole:

Trivially easy to bribe employees: Check.

Yes ... but, if the hacker didn't have access to the employees ...

BTW, would this be considered a denial of service attack?

Not worth $3500 to find that your employees can be bribed to unplug a 
machine for $10, though.


Post a reply to this message

From: Orchid XP v8
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 14:14:05
Message: <4818b6ed$1@news.povray.org>
Mike Raiford wrote:

> Not worth $3500 to find that your employees can be bribed to unplug a 
> machine for $10, though.

Apparently in a recent experiment, 80% of office workers were 
successfully bribed into handing over their password in exchange for a 
free pen. [Yes, a cheap 20p pen that you could buy in a shop for 20p.]

What the report *doesn't* say is how many of the passwords thus 
collected were actually _valid_. ;-) I like to believe that office 
workers are actually that smart. You know, for my sanity...

-- 
http://blog.orphi.me.uk/
http://www.zazzle.com/MathematicalOrchid*


Post a reply to this message

From: Mike Raiford
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 14:50:50
Message: <4818bf8a$1@news.povray.org>
Orchid XP v8 wrote:
> 
> Apparently in a recent experiment, 80% of office workers were 
> successfully bribed into handing over their password in exchange for a 
> free pen. [Yes, a cheap 20p pen that you could buy in a shop for 20p.]
> 

Somebody offering me a free pen in exchange for a password is likely to 
hear the words "Go to hell"

But, that's just me. :)


Post a reply to this message

From: Mike Raiford
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 14:52:14
Message: <4818bfde@news.povray.org>
Orchid XP v8 wrote:

(Added)

Of course, my wife knows my passwords for the computer at home, so I 
suppose I am susceptible to a social engineering attack, too .. :D


Post a reply to this message

From: Nicolas Alvarez
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 15:15:07
Message: <4818c53b@news.povray.org>

> "Go to hell"

Ah so that's your password?


Post a reply to this message

From: Stephen
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 15:17:04
Message: <ochh141gdb24kgkqma6cpm6a76e7ob73fo@4ax.com>
On Wed, 30 Apr 2008 13:44:27 -0500, Mike Raiford
<mra### [at] hotmailcom> wrote:

>
>Somebody offering me a free pen in exchange for a password is likely to 
>hear the words "Go to hell"
>
>But, that's just me. :)

And me ;)
-- 

Regards
     Stephen


Post a reply to this message

From: Gail Shaw
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 15:45:10
Message: <4818cc46@news.povray.org>
"Orchid XP v8" <voi### [at] devnull> wrote in message
news:4818b6ed$1@news.povray.org...

> What the report *doesn't* say is how many of the passwords thus
> collected were actually _valid_. ;-) I like to believe that office
> workers are actually that smart. You know, for my sanity...

A few years back, I did a test on password security for an app I was working
on. The data in the DB was very important and very sensitive. They type of
data that the competitor would love to see. (Mineral resource exploration
data)

I managed to gather 35% of the passwords with a dictionary hack, including
that of the chief geologist, and another 10% by wandering through the
offices upstairs, including that of the manager of the division.


Post a reply to this message

From: Eero Ahonen
Subject: Re: I don't know what's worse ...
Date: 30 Apr 2008 15:47:29
Message: <4818ccd1@news.povray.org>
Mike Raiford wrote:
> 
> Somebody offering me a free pen in exchange for a password is likely to 
> hear the words "Go to hell"

I'd give him/her a password. A real password, a one that's so cryptic it 
doesn't even match any system out there.

-- 
Eero "Aero" Ahonen
    http://www.zbxt.net
       aer### [at] removethiszbxtnetinvalid


Post a reply to this message

Goto Latest 10 Messages Next 10 Messages >>>

Copyright 2003-2023 Persistence of Vision Raytracer Pty. Ltd.