Re: Interesting discussion on ServerFault regarding an idiotic auditor ...

Dave Kahn <[email protected]> Thu, 28 Jul 2011 19:43:32 +0100
Newsgroups gmane.comp.systems.as400.security
Message-ID <CAD_Anen55EFdMwauaoyiUM8yDt6SA9KSEbY4cmdvbo3Ye-_saA@mail.gmail.com>
On 28 July 2011 03:20, Douglas Handy <[email protected]> wrote:
> Jim,
>
> I would think that kind of request is a hacker seeing how stupid a securi=
ty
>> manager can be..
>>
>
> It is either that, or an attempt to determine if the security manager can=
 be
> "socially engineered" and persuaded to give up information he shouldn't. =
=A0It
> at least has a small chance of really being part of what they are testing.
>
> But I give it much higher chances of being a hacker, and not really even
> from the alleged audit firm.

It can't be a legitimate request from an audit firm as it would be
illegal for the firm to make it in the UK. If not illegal it would in
any case be unethical as it would seriously undermine the client
company's security even attempting to comply with it. Whoever asks to
see a plaintext password?

> I give it a near zero chance of being a serious auditor who is serious ab=
out
> requesting the information. =A0What probably troubles me the most is this
> security manager would even consider trying to fake some data to hand ove=
r,
> instead of steadfastly refusing to comply and informing higher ups and the
> legal beagles.

Do we know if the poster is genuine? The whole thing sounds made up to me.

-- =

Dave...

Two is not equal to three, even for very large values of two. -- Grabel's L=
aw
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) ma=
iling list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.