Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why was there a public endpoint?

Surely this should all have been behind the firewall and accessible only from a corporate device associated mac address?

 help



> accessible only from a corporate device associated mac address

Like that ever stopped anyone. That's just a checkbox item.


wot?

I mean - do you have the macid's of McKinsey's corporate devices?

After a minute near one of their offices I do. Macs are either randomized per session, which makes filtering on them pointless, or they are not and still broadcast making them non secure and easily spoofed. Relying on mac filtering is usually only an audit checkbox to check. There is a reason 3 letter agencies used to use them to track people as they are really easy to get and track (until they got randomized by phone manufacturers and OS's).

I see what you mean, but then an authentication step?

Surely.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: