logoalt Hacker News

mschuster91 • today at 2:09 PM • 2 replies • view on HN

The older the system, the higher the chance it never got a proper security audit, and/or it was built with a lot of implied trust, like most old Internet standards are.

As for 2FA, it is a nice thing to have, but it comes at a significant support cost. People lose their token, people get annoyed by the friction, people can't figure out setup (especially older folks).


Replies

_bernd • today at 2:15 PM

That's not how auditing works as I have observed it. Either your stuff is critical, or not. And when it is then everything which touches data sees an audit and no password policy incl. Shared and weak credentials is the first thing that would have been spotted. I would assume they buried some stuff to deep in a hierarchy and 3rd service partners that this company in the end got no proper audit.

edoceo • today at 4:04 PM

Oh no! Cost! Friction! Better just half-ass it then.