this post was submitted on 30 Oct 2024
194 points (99.5% liked)

Technology

59392 readers
2738 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Fosheze@lemmy.world 29 points 2 weeks ago (2 children)

Yeah, the proper time to revoke credentials is before they even know they're getting fired. At all the places I worked, the first sign that someone was getting fired would be that they're suddenly unable to access anything.

[–] AngryishHumanoid@reddthat.com 14 points 2 weeks ago (1 children)

It's likely that HIS credentials were revoked, but anyone in IT will tell you there many systems which are accessed by a shared direct username/password login, and yes while that should be changed when needed a much easier solution would be to lock those apps/sites behind a VPN which is much easier to revoke access to.

[–] Fosheze@lemmy.world 13 points 2 weeks ago

Exactly. Nothing with shared credentials should be directly accessible to someone off site to begin with. Either way things went down they have a security hole you could fly a blimp through. Either they aren't revoking credentials properly or they have eternally facing systems using shared credentials.

[–] calabast@lemm.ee 10 points 2 weeks ago* (last edited 2 weeks ago)

IT systems need a way to pre-enter an account deactivation, and when HR sends a text to the system it makes it live, or something. I've been the IT guy who was told to disable an account, and the user found out before the news was broken so they asked me what was going on. No bueno.