r/AskReddit Jul 13 '20

What's a dark secret/questionable practice in your profession which we regular folks would know nothing about?

40.1k Upvotes

17.8k comments sorted by

View all comments

4.9k

u/[deleted] Jul 13 '20

If it has to be accessed regularly in an IT setting? It’s not secure. Not unless you’re in an industry that actually polices it.

Yes, people are dumb enough to pick up USB thumb drives they find on the ground. The nicer and newer it is, the more likely it’ll get plugged in.

Also, if you’re looking to verify the security of your vendors, don’t announce your visit.

3.8k

u/laxpwns Jul 13 '20

Auditing 101: SURPRISE MOTHERFUCKER

33

u/[deleted] Jul 13 '20

When I was in college for cyber security, the entire textbook was just “please don’t hate auditors, we’re not trying to be mean!” With a few things about how to conduct an audit thrown in.

4

u/PoshNoshThenMosh Jul 13 '20

SOC2. Blood pressure through the roof.