• Deadend [he/him]@hexbear.net
      link
      fedilink
      English
      arrow-up
      93
      ·
      9 days ago

      It’s not an intern. A major company at Ford’s scale does not let an intern post.

      It’s likely an unauthorized access. Ford has a lot of IT security, but it’s the kind of security that is so secure, it becomes insecure (many passwords, very frequent password updates, which lead to people just writing the passwords down).

        • Deadend [he/him]@hexbear.net
          link
          fedilink
          English
          arrow-up
          29
          ·
          9 days ago

          I can’t say for sure. Please post screenshots and I’ll let you know.

          But it is a real Security issue, where the org has such a strict policy on ALL users to maintain a high level of security hygiene that it’s impossible to keep up with while doing normal work. It’s why there is such a big push for SSO systems/portals. As that way you can have 99% of users be kind of dumb - as long as they use your company portal - they should be good… and a smaller team focused on the security of that portal and looking for odd login actions per user.

          • invalidusernamelol [he/him]@hexbear.net
            link
            fedilink
            English
            arrow-up
            13
            ·
            9 days ago

            Requiring rotating key/authenticator access for remote work and allowing users to come up with a solid terminal password on local access is pretty good.

            That way all local connections can be verified and remote logins have the extra security layer.

            That being said, if a priveleged user manages to compromise their local work machine it’s all fucked.

            • Deadend [he/him]@hexbear.net
              link
              fedilink
              English
              arrow-up
              2
              ·
              6 days ago

              That’s where security experts who are checking for things to go bad come in.

              Making everyone a security expert + doing their job is some uphill ice skating.

              • invalidusernamelol [he/him]@hexbear.net
                link
                fedilink
                English
                arrow-up
                2
                ·
                6 days ago

                A good bet it to open a dummy ssh port that no one should ever connect to, then immediately add any ip that tries to connect to it to a blacklist.

                At the end of the day every security measure can be bypassed, you just need to be prepared for that inevitability.

                • Deadend [he/him]@hexbear.net
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  6 days ago

                  Locks are based on time/difficulty/detectability in the real world. The goal is “can’t to break in without getting caught”

                  It’s all a balance between risk/security and actually being useful.

      • Dessa [she/her]@hexbear.net
        link
        fedilink
        English
        arrow-up
        17
        ·
        9 days ago

        I work for a company with that sort of security. It’s infuriating and many people miss hours of work because they need IT’s help to get back in every time there’s a password change.

    • Sulvor [he/him, undecided]@hexbear.netOP
      link
      fedilink
      English
      arrow-up
      65
      ·
      9 days ago

      Yeah it’s good to remember that while we might hold some pretty fringe opinions here, the belief that Israel is an illegitimate terrorist state is nowhere near as fringe as it was a year ago.