logoalt Hacker News

madaxe_againtoday at 5:32 PM1 replyview on HN

Hah. This is nothing.

I know a blackstone company, who were a client of mine before they underwent a hostile takeover (blackstone fired everybody).

They claim to be ISO 27001 certified. They are not. They never removed me from their ISMS, and I can see it has not been touched in three years now.

Wait, it gets worse.

My root credentials still work, both for the app, and for AWS. Nobody has logged into AWS in years (hey, we built a reliable system).

I have unfettered access to highly sensitive (in some cases literally classified) commercial data for the likes of Apple, Siemens, Philips, BAE Systems, Raytheon, and more.

Wait, it gets worse.

They did something to the API endpoint. You can now bypass authentication entirely and anyone has access to this data.

Anyway. Bunch of shysters. Incompetent shysters.


Replies

lightedmantoday at 6:50 PM

If what you say is true a report to ISO themselves will strip their certifications away and make them toxic to other businesses.

show 1 reply