24
U.S.: Chinese state-sponsored spies spent 4 months in aerospace firm’s server
(www.theregister.com)
A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.
Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.
Subcommunities on Beehaw:
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
I think that there are two ways to solve that.
The first is to have the admins actually complete setups.
But, humans being humans, maybe the second is a better approach:
When creating a computer system, don't let a system be used, at all, until all default credentials have been replaced with real ones. If you do, someone is invariably gonna screw it up.
Your directions may say "Before pulling lever 2, pull lever 1 so that machine does not explode". And maybe you feel that as the manufacturer, that's covered your hind end; you can say that the user ignored your setup instructions if they get into trouble. But instead of doing that, maybe it's better to not permit for a situation where the machine explodes in the first place; have pulling lever 2 also trigger lever 1.