1/13 So, this week I discovered my first #serious #security #vulnerability in a public system.
In the past I've found #problems in #software, problems with #websites, with bureaucratic processes, some of which were significant, but they all pale in comparison to this one.
It starts with a #chain of #pharmacies.
13/13 This isn't a mom-and-pop operation; it's a very large company. Somehow, this #design got through #meetings and #proposals and #committees and #design and #implementation and #review and #testing, without anyone pointing out this #flaw?
Or, more likely, low-level employees or contractors tasked with building it did see the problem, and maybe even said something, but #management #ignored it.
I will post updates when I have them.
@cazabon Thanks for this info. Good thing you know enough to raise a red flag. Most of us wouldn't. Wonder how they'll respond??
I wonder that too.
I'm guessing it will be one extreme or the other - they'll "OMG!" and temporarily shut it down while they fix it (which I suggested), or they'll #stonewall, #deny the problem, and #threaten me for "#hacking them".