Files
Lee Hanken 087f80c44d Update metadata and transcripts through end of July 2026
Refreshed episodes/hosts/comments/series from hpr.sql, and added
official HPR transcripts for the 180 episodes aired since the last
sync (hpr4516-hpr4695).
2026-07-31 16:18:57 +01:00

452 lines
40 KiB
Plaintext

Episode: 4615
Title: Clicking through an audit
Source: https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4615/hpr4615.mp3
Transcribed: 2026-07-31 16:15:11 (official HPR transcript)
---
This is Hacker Public Radio Episode 4615, for 2026-04-10
Today's show is entitled, "Clicking through an audit"
The host is Lee and the duration is 00:57:58
The flag is Explicit, and the license is CC-BY-SA
The summary is "Lee complies with a company audit by clicking 'next' a lot"
hello this is Lee today going to kind of walk through the stages of the administration around
complying with a security order as an individual employee whose company has been audited and
the standard that they're using is ISO 27,000 and one. So you know they've been given what is
turned an information security management system and that's a specific term that has been
established and now what every employee has been given a checklist effectively or a set of
training to go through and you know just see what their compliance is because right firstly I
don't think it's sort of expected to be perfect from day one you know goodly it's a process
it's not like you tick you tick the box once and then it's done and also it's like it's
a responsibility of everyone in the company it's like from the directors to every employee
turn them up a computer and I've looked onto the internet and I go to my training dashboard
and there's 12 outstanding items that I have to go through and these are ISMS portal access
information security management system and actually they're they're actually a company
who have taken that on it's their name quite cleverly and policy pack and knowledgeman
change management and secure configuration secure software dev security basics access control
and lease privilege data classification and handling passwords multifactor authentication
security security incident reporting and response phishing and social engineering awareness
secure remote working in mobile device security they protection and privacy GDPR awareness and
sure no it doesn't know GDPR is the general data protection regulation which this came into
force prior to the UK leaving the year and it was you know when Brexit happened then it became
in this country the data protection act 2018 but GDPR was the big push that came around
the towards the end of the last decade to really take seriously how people's data was being used
and it while it was kind of European ladies had global impact anyway so the other training
item acceptable use of system and information security awareness and apparently that's an annual
thing because it's got in quotes annual so going to the first item in the outstanding list the
portal access and policy pack and knowledgeman so it's as login to that I did before but
let's just do it again to make sure so it goes to the website of and this and I'll go to login
except some cookies the click login except as some cookies then what right after login again
go to last pass try and find what my password was and of course it says unsuccessful because
always is facing the email address it's in my password again from last pass remember they see
my address I guess login no so what can I do all right it gets us if your organization is using
our EU dense date center please sign in here they could have led with that and I still sign
in unsuccessful need help looking in and to your email address okay it's the company in my address
so email mail link to reset my password it says if this is good if the email was registered
then we've emailed your link yeah if it wasn't registered you're just elistinating or you
some bad hacker person trying to login such is a good team out choose the thing and it says
we've locked your that's lovely I mean this is beautiful isn't it we've locked your account
and it's in reset your password I mean it's not like I like swearing and it's not like I like
using for little words but I have just internally uttered one describing the people who's out
the system he is the same email that's registered you know it's spelling of your email address
no email link in a second time of asking that so even Gmail thinks this is spam so
had I tell you it's not other show images okay for some reason that show me an image of their
logo like that was important enough to cause me to have to go through the show images thing
that they had to include an image right I've got a link in trainee password well
I don't know intranue password paste in the same password that change password yeah
great it worked okay this miss um so I'm looking at my my first one is 9 shape sent in the
way for a it's called development and of course the truth is I just when you're doing
that something like this the truth is if someone if someone gives you a list of 10 things to do
you will do those 10 things someone gives you a list of 100 things to do you will just click
through them you know I'm sorry this is human nature and you know they should know this
very very well you're just click click click click click click click click click you know I can't
actually see what's going on because my dark mode is interfering but actually these are ticks I've
got ticks against everything but why is it saying there's number 92 isn't done so it was social
social media guidelines so I mustn't bring the company into disrepair by criticising
our argument of customers, colleagues or rivals making the famigy comments about individuals
organisations or groups or posting inappropriate images or links to inappropriate content okay
well they got fully breached that already just by recording this policy pack overview
it's not letting me get out the last policy and I think I had this it was like an empty
it was a boiler plate one your policy packs and our value was an app that you can install in your
device it's not going to like increase the risk of my device to install their thing on my device
did I close that right let's actually go through what these policies are so introduction
policies and controls policies for information security information security roles and responsibilities
segregation of duties management responsibilities content with authorities content with special
interest groups threat intelligence information security and project management in the trip I mean
you know this but living in another universe yeah fine if I mean if I can think of how to do better
I would do how would I do this better or not give someone 100 things to click for a
literally a hundred well 91 92 if you count the one that's broken looking for those is there any
that is actually hyper relevant that's something I don't already know I mean yeah this is fine
but it's boiler plate you know I should not be I'm not talking about means particular but
and employee should not be given stuff that's actually outside their control like access rights
and it's like a broad policy about access rights it's like you know denied by default need to
know need to use least privilege privacy by design privacy by default access provision
access modification access removal privilege access management roles and responsibilities
and actually they've got some specific information about who's has different roles which is useful
but apart from that it's a boiler plate and it's a completely outside of the person clicking
for it this and I'm assuming everyone in the company has to click for it this is outside of their
control it's like saying I don't know account provisioning is automated for integration with
the HR onboarding presence and it's like okay that's fine I'm happy with that but why am I
having to click for it because it's completely outside of my control what the HR onboarding
process it's I mean fine this is this is in one place but I should not be the person clicking
through something that I have no control over and then you know and somehow that it means that the
company is compliant because someone who has no control over something clicked through something
telling them stuff they have no control over and I'm not criticizing the terrific company
I'm not even maybe criticizing the this particular provider of the security policy I'm just saying
that it's a bit ludicrous for an information security management system to be presented in this way
to people it needs to be a lot more relevant it needs to be like 10 bullet points of what is actually
relevant specifically to you not this is the entire policy read it through and yes it's here as a
reference and that's good that it's as a reference but anyway I can't complete this because it's
and I actually told my supervisor he got stuck at this point so is there anything else
I'm like again this website it's got no navigation so I don't know how to get back to where
was it here we go is the dashboard so it's a two list I mean that's useful let's give me a two to do
list information asset inventory is interesting this is quite good actually it's got like
some third party systems listed like accounting systems it has things like you know the card
that would get you in the office it talks about the code repository and for each of these it says
whether confidential or sensitive and like customer data and database is what do they mean by digital
certificates it's a I'm unclear that specifically what digital certificates it's referring to
if it doesn't mean writing encryption keys and see what I'm actually looking for is my
private keys that access the server because that's actually something I have a reasonable level of
concern over office keys physical yeah so all right so I'm sorry I'm rambling but for each of
these information assets we have like the name like backup data we have it a status or it's
to do or live a financial value and that seems to be left blank and then the type of thing
that it is is it staff as a physical security as an infrastructure as a person of data
is it software application and services and then as a classification as it is sensitive or confidential
or public and then we have its primary location like third party data sent to or in person
and then you have the owner of the lead so is it the CEO or the chief technology officer
and then it has an RTO it's going to tell me what RTO means it has an RPO have to look nice up
have recovery point objective all right how long right so if this asset get got lost how much
data which you lose which you lose a day a week a month or everything yeah I don't know
and what's it was RPO so it's RTO there's the downtime so how long until it's back online
so like if you lost it how long will it take you not not just how much it
RPO is how much you lost and RTO is the recovery time objective which is how long will it take
to actually get it back working and then it has the lead wire no like who I'm this thing is
of the companies that supplier or I guess is it the customer or someone else and then it has
an assignment so it's a scientific and a member of staff some particular person is on the list of
what they're responsible for so okay and back here seems like it's in that's at 99% and I'm sorry
the the asset inventory doesn't have percentage on it so the policies and controls that's at
90% have I don't remember actually looking at that okay it's popped up around and pop up
that you just get rid of because I can't even figure out what the pop up is trying to tell you
it's just in not that it's not in English it's just the English the English does not
process as to anything that I know what it's talking about so it has requirements and it has the
number 4.1 to 10.2 organizational controls people controls physical controls technological controls
addition so control is basically what we're doing to make sure that things are secure and that
and this is what I learned when I was doing the post-graduate course in information security what is
a control and most of these are showing us being complete I wonder if that's truly the case that's
what it's showing or like most of them I like that could be that 99% of 99% of them are actually
trivial and just require a tick by someone and then like the other 1% require masses of time and
effort to do so whether this percentage truly represents the security of the organization I don't
know all right I mean I've done everything on this I can so I'm going back the inter
closed all these tabs you know people get annoyed when I close their tabs and I can't work
with with more than one tab you know once I've once I've done with the tab it gets closed
so I've done the policy pad read the policies mark the policy pads read I'm not sure I did this
try to and then it says start the course it confirms that you can access it oh no they're not
going to ask me to give them a screenshot to prove that I accessed it please no it's not all right
so I can successfully access it yeah acknowledgement I've read an understood yeah kind of yes
evidence optional yeah they they want a screenshot and it says optional but I you know I'm going
out by the screenshot so I've got I've got my nice little dashboard here from the compliance website
what screenshot you've got I've got spectacle so let me just grab the active window so click on the
active window and it's just grabbed it I had a one second did I have a one second delay I
give me a chance to like move my mouse out the way or whatever although when you grab I think
when you grab the active window it doesn't capture your mouse it's a save as shove on the desktop
because it's screenshot do you what does it call it so it has the day in as in the four
digit year the two digit month and the two digit date and then it has a number it's maybe the number
of seconds zero nine three three one zero because 86 something thousand seconds in the day so
now looking through looking up while a little clock here using the time system or friend Ben I
invented and it's three sevens of the way through the day so how many seconds it's going to be like
out by six thousand we thirty thousand seconds so I don't think this is the number of seconds
Ben I's given it a number zero nine three three one zero in the screenshot you'll be
interesting to know how those screenshots are derived a screenshot font names right so save that
saved go back to there I should drag the image on here and then was the okay
bum that it's safe comments okay so let's just say it seemed the last policy could not be
access I can down like this course material so it's open it in a new browser window and then
I click on the download link I think I've got a security folder so I'm just dropping it into
there I've got my own copy of it and click and complete and that's completed I said it would take
five to ten minutes so you look at it longer so once done now I've only got 11 outstanding out of
12 so now the next one is change management and secure configuration right so you know learning
objectives modules why change control matters yeah avoid unsafe shortcuts document changes
appropriately prioritize secure configuration so it's good so when subversion I don't know
that way so when subversion can be fucks up everything I mean right this is my my human
experience of version control systems like get and subversion they work fine until you just
accidentally click or type the wrong thing then you're in the world of pain and you're then
spending hours or whatever trying to undo the thing that you've done like I accidentally on subversion
I was gonna use a change list so I was only gonna commit the few changes that I wanted to
and leave out the files that didn't want it to because I was working on two three different
projects at once then one of lumped them all into one commit and I accidentally committed everything
and then you go to like google you go to um large language model and you say like right how
do I undo this and it says oh to undo this just type this and it's a type here and oh look it's
screwed up even more and then I'm not like saying tell it well now this is what the situation is
I'll now just do this and so I can't do that and now it's completely fucked up beyond the
recognition and in the end you end up you just I think I'm just gonna
nuke from all the I just completely abandoned the repository that was on and create a new repository
a new development branch and just reclaim the development branch from the
source and then just copy my files that I've got you know on my own like machine
copy the files that you've been working to back on and of course you know because I've just
just because of because I've now got the latest code running you know there's configuration issues
because I've failed to coordinate with other people in the team who have updated the data by schema
and so the you know the entire my entire development platform is now not working it's now down
because it's falling over something and the schema is different and not in line with the code
so I mean that's that's the reality of third of I guess they call it change control version
chart I mean the lucky thing is I just have not been given access to anything where I could
damage a production system I could damage my own system and to some extent I could
insert unhelpful data you know by mistake into the shared the shared where we keep the
database not the database schema not the level I level one but the customer level database schema
and the you know the different templates and forms and how they're managed how their
data is synchronized between different instances of the server there's a central location for that
and yeah I could in some way insert things into there then there would then you know need to
kind of undo that and restore that because then it makes it unusable for other people if they
wanted to sink from it but you know I'd have to be willfully and willfully stupid if I was
doing that so all right so I'm just looking at the learning objectives for this yeah I mean yeah
back in the 90s I worked a company that had proper change control and it was as in you know
in in in in some ways it kept you safe in other ways it's and as annoying as hell if you make a
tiny little error and it means you're having to walk through the entire change control
processes taking two or three days you have to get customer approval again just because you
made a typo that you didn't spot and it didn't get spied until later in the change control process
and you know probably reasons like that that you have this is why they invented DevOps
is to reduce the amount of friction for developers while keeping things reasonably safe for the
ops team that things are going to kind of flow and not be complete headache and then I like
this is like if there's an emergency change you still you have to like because you know there are
times when a production system actually needs an intervention there and then and you can't go
through the whole change control but when that happens that the same that needs to be documented
and followed up you know that's a nice happy wish I would say change management school not
to check all right here's a quiz right why do we change the control I love this to slow down work
I mean honestly yes yeah we're still to reduce attitudes yeah and security risks and improve
accountability right misconfiguration is a common course of incidents yes all right some bit you
know can do this quiz all right I'm spacing right secure configuration practising include
default deny and release privilege I guess yeah disabled unused services yes public by default
for convenience now avoid public access unless and quiet and approved yes after deploying a change
what should you do I think we want to invalidate emergency changes should be documented
good rollback plan is and now not wait to refer on where to go quickly okay so I've got to take from
that month that is complete cause it's completed to significantly less than 23 minutes I don't know
what my past month was didn't tell me what my month was they said the past month was 80% cool that
once that's off the list so secure software dev security basics protects secrets and credentials
never encode tickets or chat by secure coding hygiene validation or frozen what is off said me
no okay don't know offset what is off said in information security which means authorization okay
I've got feeling in English in the English language authorization has got an S I think often
not try and use the American version cause when you're coding you try and use the American English
like color no color right when it's dependent since supply chain that's yeah okay
understand what that means I use code review and continuous integration controls to reduce
vulnerabilities code review yes C I controls I don't know if that's kind of a happy wish at this point
avoid risky logging and sorry I'm using the word happy wish I just wish the original
then even know where I got that from what is the origin of the term happy wish and how does this
seem to be keep coming to mind as I fail in the information security or the compliance
question it tell me it's a psychological reaction to inherent tension of compliance work
is a gap between policy and reality aspirational compliance you may be looking at question
like are all administrative actions logged and reviewed weekly and thinking I wish they were
or in a perfect world they would be the checkbox track the term captures the feeling of providing
a happy answer yes we're doing this well internally now it's more of a wish than the consistent
enforced control it's a mental shorthand for wishful thinking masquerading as a security control
I mean I've been doing this for like a half and 25 minutes I've already got ordered with
he so I can well let's start the course I mean ideally it should be prompting you to
actually do something not just think I'll idea so here we go knowledge check I mean it was telling
me stuff I just give that go straight to the knowledge check right authentication is
who you are authorization is what you're allowed to do if you're an authenticated they can access
any object of the name where should secrets not be stored when a QR code on your front door
that source code repository is tickets chat see I've got all of the above
and except for the approved secrets manager you accidentally committed the API key
I revoke and rotate as I find side validation is sufficient yeah no it's not it's not
best protection against SQL injection yeah prepared statements I don't see that a lot in the code
place supply chain risks include what is type I squatting all right okay you give you the
main like google dot com you go to google dot com you type in some secure information
come for myest maintainer accounts code reviews in the risk it's negative
pinning and reviewing dependency changes can reduce risk yeah pinning is where you fix it
certain version you don't just automatically update to the next version until you've decided that it's
safe to do so yeah they're talking about pull requests here that that may exist on
may exist in other parts of the universe it I've never seen it in this context so why
while do we disable CI checks ask for justification yeah least privilege for service account
remains I give any permissions needed right production access should be limited in the trial
to guess yes good logging practice include for that thing yeah deadlock for personal data
payloads control access to logs yeah using production data and development is yeah with approval
controls temporary secrets in code all right I mean I might disagree with this it depends what
codes but okay yeah not acceptable anyway I can download that PDF save it I think that one's done
that click on complete or I'll neatly the deadline is the first of April but I'm down to nine
outstanding things so access controls in this privilege right it's a completely skip everything
I just click start course completely skip everything down to acceptable use of systems
that owned by the organization personally use maybe committed a bit of different ways in the
level well I use chat GPT to write a book then I have that's reasonable okay which statements
about monitoring privacy is most accurate personal information accompanied devices is private
I'll be going to ease confidentiality of personal information accompanied may want to
use the school Jamaicans to not assume privacy I think getting stressed about protecting
your privacy just come to accept no just never ever assume privacy ever never assume it
selectable good password practices keep passwords and authentication in face secure
and then I guess I share your account now is MFI yes yeah doubt approval once you didn't
initiate doubt share the codes good right when should you lock your screen I heavily disagree with this
if there are other controls in place because there are situations you do not want to be
unlocking your screen every fucking five minutes you know because for the sake of the little
sanity that one has left right only at the end of the day whenever you step away from your
office your device yeah all right I mean yeah if I'm sharing this if I'm physically sharing the
space with other human beings yes I will want to look my screen I guess if I'm not sharing
you know well one my mom may be a secret hacker for the Russian government you know
I'm pap she isn't right do you want to instill a new tool on your laptop
what should you do yeah get permission I don't I don't have a laptop or I do but I don't use it
okay right select elections that reduce risk yeah why about touchments and verify unusual
requests yeah I mean this was I was not I don't know if I was not thinking I actually just
like I was working an unusual location I did not have my public key for my device I was working
instilled on my dev server so I just emailed my colleague and said I can you shove this
public key on the dev server and you know he did it but he was like they he came it's actually my
self fuzzy he came to me it later and he said actually that seemed a bit like a fishing attempt
and I just only realized oh yeah my ver well it was convenient because it allowed me to get some
work done that that it didn't actually much big I didn't actually do much that day so it wasn't
necessarily all that useful and I think next time I think I might just say well if it's not on this
device I just not not work at the moment I just leave the work for a time that I'm actually at
my my own device so I think part of fishing is not just don't be fished yourself but don't ask
other people to do things that they that they themselves will find a comfortable I don't know
and I've got an email just seeing if this okay just confirmation that something will be passed
on to the relevant person but we're talking about why I shouldn't have reduced my risk
don't forward customer files to personal email well I mean I use I'm sorry but
if it's not on my personal email don't see it and well these are not customer files these are
these things like API specs or and I just general discussion it's not sensitive information right
checks and address carefully yeah okay is acceptable to let a family member use you work can't
probably not which is prohibited reports using malicious introducing malicious problems it's
systems I mean I can't imagine what would be wrong with that I mean I think wished in in still
the virus and that every system you have access to it's just a matter of course
port scanning or security scanning a lad with prior authorization
but I'm gonna click this one but I'm sorry I'm never ever gonna use any computer system
that I have not scanned the ports of I mean I'm sorry that's just it's in my blood you know
I will always scan the port right you receive an unexpected invoice attachment from an unknown
send a reporting of I don't mean you should I need you should only access systems and that
you're offers to use yeah making fraudulent offers I guess prohibited select or
prepped installing part of software things in your definition but yeah sharing passwords
the nav service attacks keeping your device updated and accepting network traffic not intended for you
I I question whether intersection network traffic not intended for you is really prohibited
I mean if it's not intended for you it should be encrypted not that I've ever done this but
don't put it on me to to be accountable if someone is not if I'm having to use some system
and this is not a specific example of something that's actually happened but if I'm using some
system and someone is not encrypting their network traffic it's almost my duty you know it's
oh yeah I should downwell intercept it and downwell tell them by the way your traffic is not encrypted
yeah I don't know you know I tell you this I take it seriously but if someone's telling me
something that has right I'll have to chat get my thoughts clarified on this right right I am
told in an info set or it never to intercept network traffic not intended for me I have
crimes this will be negligent on my part not to be aware of potential hunting
cryptid traffic on the network I am connected connecting to as if a security risk affects
someone just on the network it then well affects me also so I say there's a
monitoring for safety versus another threat's intersection I mean they're saying right I'm
getting private data passwords emails are personal browsing of colleagues but I'm not because it
is it should be a secured HTTP you know secured DNS oh yeah trigger an ideas an
intrusion detection system I forbid sniffing traffic so it's not it's not necessarily because
there should be encryption at the app level and endpoint prediction well this is how it puts it says
the order isn't asking you to be negligent it's asking you to respect the boundaries of
authorization think of it like a hotel you should lock your own door and report fire in the hallway
that you aren't allowed to put a glass to the wall to listen to what's happening in the next
room just in case there's a thief in there yeah okay like I don't want to sneak on anything
and I inherently would not would not but if network traffic is passing through
my system such that it can be sniffed it is inherently no longer private it is part of the network
traffic I would not on principle try to sneak but I need to be aware of what is going on
the network because it also affects me so this depends on putting your network card into
promiscuous mode yeah all right so I'm not putting my network card in promiscuous mode
what prevent someone else doing so I mean all right it's their risk and it's not my responsibility
so yeah you can use ARP watch your neighbor discovery egress monitoring to see what I'm sending
out through to call auditing so yeah I can it's a user scanner don't sniff but
so say the professional approach is too yeah and what do they mean by intercepting network traffic
that's not intended for you as as difference between intercepting and I mean I'm stuck at this point
because I think there's there's something important there's not being expressed or discussed
but the idea that capturing traffic going through my network the interface on my hardware the traffic
is reaching the interface on my hardware that I should not be allowed to
register that data if it comes to my hardware I find hard because you know if I'm working for someone
it doesn't matter what it is I am not going to even look even if I have to process something
there's I'm going to look at anything that's private to that person or to that company or whatever
I'm just not going to do that okay the next section is data classification handling and this
has questions why do we classify information and that's like is it public as a confidential whatever
incentive what sort of information should be restricted like passwords API keys
should be confidential files in personal cloud storage now
had to share a customer report internally but on some approved storage somewhere
so good practices for confidential data at least access need to now
remove access for no longer needed large exports of personal data or confidential
screenshots can expose data what's the best rule for export so I export the minimum
so what common lead points so screenshots log status ports so if you accidentally shared something
a link should provide kit and restrict access and report to what happens
personal data should be confidential yes restricting information should be shared
should be shared and you've all fried people and type with type controls
it's fairly straightforward so passwords and multifactual authentication
if things like the biggest risk of reusing password is the one breach can compromise
more than one account so they use this even a strong password they use it everywhere
best way to create passwords password manager generator
for your password manager use a strong password and they say lock screen and multi-factor
I think biometrics nowadays is probably what you should be using so multi-factor
have protect accounts even if password is less stolen yeah so if you receive a multi-factor prompt
it's reported you know that you didn't initiate your report here and check the account security
you know what is the past phrase you know is is a predictable pattern a good password
well in principle no but sometimes sometimes there might be the best solution sometimes
there might be a more human solution but it actually works better so who had enough accounts
been compromised you get password reset and they didn't request looking alert or
you're forwarding rules created and that you didn't do if you accidentally put the credentials
in a suspicious page you should report it and change your passwords they have a share passwords yeah
I mean the kind of repeating themselves a bit but the next section is security
instant reporting in response so apparently as well security instant is any event that could
affect confidentiality integrity or availability if you're not sure they'll just wait until you are
sure right which of the following is an instant a last laptop and expected them a fake prompt
I extend the mainly customer report suspected malware warning okay that some of this is just
repeating themselves so don't don't destroy evidence unless instructed so evidence could be screen
shops email headers or message IDs time and date of the event so the device is done what's your
first action report it using an instant process the instant process is that one
extended data sent to the wrong person can be a personal data pressure
been how many how many times as everyone received a CC of people's email addresses which was meant to be a
CC I mean literally how many times that happened and then one person replies to it and right
sends out a 2350 emails to everyone else in that CC list I mean you would almost think they should
build it into the email client no one in their right mind wants to see see more than like two people
you know it's never efficient social engineering awareness so
efficient what is efficient trying to do is trying to trick you into a really information
take unsafe actions commission reflects could urgency and pressure are requesting passwords or
MFA codes look like the mains to good to be true offers so see how usually I see to buy gift cards
which should do verify if I'll independent channel yeah now my sport worker he got
fine cool telling him he owed some tax you know they said try your credit card and then he gave them
their credit card number and then they said oh that didn't work we'll have to find another way
you feed send us the tax that you are us I tell you what why don't you just buy Amazon vouchers
and they got him to buy 4,000 pounds worth of Amazon vouchers and send them and it's only like
when he went to the supermarket the third or fourth time and was buying a stack of Amazon vouchers
they were like someone said a why do you want these Amazon vouchers and he said oh I have to
repay some tax and the person said no perhaps you're being scammed and he's like oh oh yeah
I guess I could be cure codes can be used in fishing attempts yeah it's quite a good one actually
supply says the bank details changed say what she's doing verify by non-channel
the best general mindset for fishing prevention is slow down verify unusual requests
secure in my working she perhaps relevant to me I don't generally go around with my laptop all
over the place it's working from a home PC mean some of these I just click for it because it's
not really relevant that all of them I click for it so data protection this is back on the GDPR again
personal data is information relating to my identified or identified person
data minimization means click only what you need for the purpose so what counts as a person
date breach sending personal date the wrong person losing a laptop that might contain personal
data posting use it in final public forum and all price access to the account I don't think
I know price access to the account is a personal date breach or is that I guess it is
storage limitation delete or I'll call for another required what's a DSAR it's when someone says
what tell me what date you have about me it's a data it's a data subject access request
so which of these roles align with the principles of data protection is data for intended perhaps
I need to keep the data secure don't keep data longer than needed yes and an acceptable use of
system occasional personal use of company systems may be permitted if it's reasonable
so let's go to good password practices keep passwords and authentication if I secure use
multiple authentication do not share multi-factor authentication code select actions there
are just email risk be careful with unexpected detachment verify unusual requests with a trusted
channel check the send address carefully port scanning is allowed with prior authorization only
you should only add to systems and date your offer as to use yes if you lose your work laptop
what should you do I think you report it okay information secure some of that seems to be
paying itself information security awareness this annual out of C I I what best describes
confidentiality they choose any accessible to CIA so CIA stands for confidentiality integrity
and authorization not a failability so I there are the three pinnacles of information security
are confidentiality integrity and the failability just in my experience of
availability is the big one because you're much much much more likely so again to travel just
not backing up then you are from someone deliberately trying to harm you or still your data
or just deleting stuff yourself by anything or thinking that you have backups that you don't
and this is kind of high level stuff like data minimization means and and you collect
new data necessary purpose the safest way to share sensitive customer information is approved
secure company systems with all price access fair enough I mean this I don't really see much
actual customer data message been filled for whatever anonymization or anyway I got the
stiff cuts go all the stiff cuts those who have a stiff cut like the or valid until
it's got the date on it yeah I mean a lot of this comes down to I know the principle
the reason for the audit is it's about protecting company and protecting customers information
even protecting your own information and being secure about how you're doing things which is
over reasonable but it touches on a few areas of it's something that is kind of incidental to it
but it's something that highlights for me is something about if you're a developer or a hacker
or whatever you know how do you act ethically and there's an episode HPR 3779 that
try recorded which is just because you can do a thing and that kind of says things quite well
and then there's HPR ego all the way back to 2009 HPR number 61 and 32 records a
conversation about computing which is kind of about Ted Queen dependence and moral autonomy
and it's sort of freedom demands responsibility and then even even the fair you go all the way
about HPR number 2 you have deep geek talking about customization the loss reason and it's like
questioning you know why why do you want to think of everything customized everything and you know
access all the units and internals of things and it's not really because just because you can do
it is because doing so teaches you why systems work as they do
You have been listening to the Hacker Public Radio podcast, at hackerpublicradio.org.
Today's show was contributed by a HPR listener like yourself.
If you ever thought of recording a podcast, then visit the HPR site to find out how easy it really is.
Hosting for HPR has been kindly provided by anhonesthost.com, the Internet Archive, rsync.net, and the HPR Community Content Delivery Network.
Unless otherwise stated, today's show is released under a Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.