Comment by criemen
3 hours ago
I'd add missing MFA as weakness number three, at minimum. Problem number 4 is that the "password" was leaked, and the company (Pays ApS) didn't figure that out. Problem number 5 - the "password" belonged to a _former_ employee. How was that account not disabled? Problem number 6 - how can a company with two employees get access to this register in the first place? Don't they need to show compliance with some security standard that would be not possible to deliver for such a small company?
If you start thinking more about this, more and more problems pop up.
No comments yet
Contribute on Hacker News ↗