Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When I was doing some consulting via RDP, I made sure to inform the client that I was about to expose things. "I am about to run strace on this web server instance. This is going to show what all the system calls are doing and how long they're taking. It is going to make the performance of this one instance very poor. It is possible that this will print private information like passwords and credit card numbers in clear text. Are you okay with this?"

I'm not sure they fully understood what they were acknowledging, but I heard back later that they were impressed with my professionalism.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: