The Dept of Veteran Affairs maintains all my health records. Let me tell you, they hire the best IT professionals ever to secure their networks. Very professional! I feel so secure!

One day I was sitting in the hospital waiting room, and I scanned the wifi network as I often do when sitting in waiting rooms. I found a network switch that was exposed via telnet with a default username/password for the admin panel.

This level of sheer laziness could not go unanswered, so I changed the password and renamed the network switch "we suck at IT". A while later in the day I passed a gentleman in the hallway who was carrying a network switch under his arm, and had a look of total consternation on his face.

Reply to this note

Please Login to reply.

Discussion

it's ok because the VA uses CAC to login

CAC was the technology that made those chips in debit/credit cards possible. It's pretty secure as a login method, but it doesn't secure my health records. The US Government's cross-origin login system is a total mess.

sir, "Wutz yor 4" lol