-
Notifications
You must be signed in to change notification settings - Fork 9
Q & A on breaches
Cris Simpson edited this page Jan 7, 2023
·
2 revisions
Two concerns:
- Access to data held by PDP systems
- Enabling access to PAWS's Salseforce instance
- Who would be in a position to detect a breach?
- How would one detect a breach - what would it look like?
- What are the ways to access the system/data?_
- Log into website (Password leak, brute-forcing, exploit login process)
- Via CfP k8s administrative access
- Via PAWS Salesforce instance
- Which access methods are easiest to allow access by an unauthorized person?
- PDP website has only password protection (no TOTP, 2FA, IP whitelists)
- What data could be collected? What would the value be?
- PDP: Names, addresses, email addresses
- PAWS SF: ?
- How can we minimize the data available within PDP to unauthorized users?
- We could truncate all tables (except volgistics) after match and push process
- Assuming a detected breach, who at PAWS should be contacted?
- What actions should be taken if a breach is detected?