Avatar

TemporaryBoyfriend

TemporaryBoyfriend@lemmy.ca
Joined
2 posts • 4 comments
Direct message

I work in IT. Most systems have laughable security. Passwords are often saved in plain text in scripts or config files. I went to a site to help out a very large provincial governmental organization move some data out of one system and into another. They sat me down with a loaner laptop and the guy logged me into his user account on the server. When I asked for escalated privileges, he told me he’d go get someone who knew the service account passwords.

After a few minutes, I started poking around on my own… And had administrative access within an hour. I could read the database (raw data), access documents, start and stop the software, plus, figured out how to get into the upstream system that fed data to this server… I was working on figuring out the software’s admin password when the guy came back. I’m sure that given some more time, I could have rooted the box because the OS hadn’t been updated in years.

permalink
report
reply

I’m truly surprised there hasn’t been a successful YouTube competitor in the last decade or so.

I suspect the problem is that people wouldn’t even pay a penny per video to content creators. From what I’ve seen of other competing video sites, there’s a really serious moderation issue stopping them from wide adoption… So many of the competing sites are full of flat earth / anti-vax / pro-fascism content…

permalink
report
reply

The best part about this is that the more they do this, the more it costs them. Every action, especially disk transactions, cost them money. Just log in every day, run your deletion utility, and cost them a couple bucks more for being pricks about it.

permalink
report
parent
reply

And FYI, the info about Signal was confirmed as they received a subpoena a couple years back, and their response was part of the public court records.

permalink
report
reply