Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another article mentioned Salesforce which has a knack for being poorly secured on the data owners side.

I’ve got another reply here with details but suffice it to say misconfigured Salesforce tenants are all over the internet.



Even if SFDC is configured correctly, any sufficiently large or old instance of SFDC may have dozens of other systems plugged into it. Many of which get default access to everything because SFDC security and permission configuration is so byzantine.


Absolutely and when throw in the ridiculous way SF does permissions AND their lack of tools for access visibility it’s no wonder these old systems stick around.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: