9 votes

Multiple Fortinet products communicate with FortiGuard services while only "encrypting" sensitive user data using XOR with a hardcoded key

1 comment

  1. Omnicrola
    Link
    "Security" like this is just jaw-dropping incompetent. It points to a critical lack of peer review in development, as well as a lack of QA and other processes. I really hope someone gets fired...

    "Security" like this is just jaw-dropping incompetent. It points to a critical lack of peer review in development, as well as a lack of QA and other processes.

    I really hope someone gets fired over this. Several someones. The person(s) who wrote it, and the person who QAd it, and the person who approved the deployment of it into production.

    5 votes