In major goof, Uber stored sensitive database key on public GitHub page

Status
You're currently viewing only Falos's posts. Click here to go back to viewing the entire thread.
Not open for further replies.

Falos

Ars Tribunus Militum
1,599
[url=http://meincmagazine.com/civis/viewtopic.php?p=28583881#p28583881:2awnyf64 said:
vcsjones[/url]":2awnyf64]
The court action revealed that a security key unlocking the database was stored on a publicly accessible place, the online equivalent of stashing a house key under a doormat.

Wow. Terrible. It's more like leaving the key in the lock. Not even remotely secure.
Echoing this. Dan may not have intentionally written it that way, but the implications of "under a doormat" will try to paint viewing as invasive. You can chase people off for digging around your porch and through your stuff.

Compares better to a key taped to an apartment door. I don't enjoy being pedantic, but the concept of "public domain" has been spun up and down into a muddy blur, so precision is chemo.
 
Upvote
14 (14 / 0)
Status
You're currently viewing only Falos's posts. Click here to go back to viewing the entire thread.
Not open for further replies.