this post was submitted on 16 Jul 2026
23 points (100.0% liked)

Australia

5074 readers
181 users here now

A place to discuss Australia and important Australian issues.

Before you post:

If you're posting anything related to:

If you're posting Australian News (not opinion or discussion pieces) post it to Australian News

Rules

This community is run under the rules of aussie.zone. In addition to those rules:

Banner Photo

Congratulations to @Tau@aussie.zone who had the most upvoted submission to our banner photo competition

Recommended and Related Communities

Be sure to check out and subscribe to our related communities on aussie.zone:

Plus other communities for sport and major cities.

https://aussie.zone/communities

Moderation

Since Kbin doesn't show Lemmy Moderators, I'll list them here. Also note that Kbin does not distinguish moderator comments.

Additionally, we have our instance admins: @lodion@aussie.zone and @Nath@aussie.zone

founded 3 years ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] MisterFrog@aussie.zone 1 points 1 day ago

What are the bets that none of the records were encrypted at rest?

Sensitive information like this really only ought to be accessible with a FIDO2 key, or something similar.

I'm not technically knowledgeable enough to know how you'd set things up, but I kinda doubt enough is mandated.

[–] Zarobi@aussie.zone 5 points 4 days ago

I got a few emails like this over the years. Like oh by the way, remember when you got bracers 20 years ago? Yeah we still kept all your private information forever and then we lost it. Gee, thanks

[–] stevles@aussie.zone 2 points 4 days ago

Unfortunately, working in IT you get the inside knowledge of how abysmal some users protect their credentials. An email comes in: “Oh no my password will expire!”, enters credentials without any consideration, 3 minutes later their emails are cloned and access to their companies system has been provided to the world.

The kicker? They don’t even report it until they notice something unusual like emails bouncing when they send out or no emails coming in, etc. Companies really need to push cybersecurity training on their staff and MFA enforcement above all else, there is no silver bullet for this sort of thing, but throw up enough roadblocks and access will come too difficult for the average script kiddy.