Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.
Advertise with BlogInfoSec.com
Kenneth F. Belva

Sharing Passwords and the Trusted Insider

InfoWorld reports that a student (Jeff Yorston) was able to change his grades because an administrator shared their password with a student (not Jeff Yorston) for a project.

But here are the key takeaways from the article:

After an investigation, county officials discovered that they hadn’t been hacked. Instead the breach occurred because of a leaked password. “One of the administrators lent her password out to one of the students who was working on a project,” LaRocca said. “That’s what happens when you share passwords. We could put $1 million worth of controls in place, but when I give you my password, all bets are off.”

And I generally agree with LaRocca when he said:

Still, LaRocca says the insider threat remains his biggest concern. “All my hackers are inside the network,” he said. “I’m not too worried about the ones from the outside.”

Post a Comment

Your email is never published nor shared. Required fields are marked *

*
*