TJX Fires Employee For Disclosing Vulnerability
I Don't Believe in Imaginary Property writes "A TJX employee was fired for an online post mentioning that TJX hasn't beefed up security after the recent, massive data breach that saw 94 million credit card numbers copied by criminals and money from their accounts stolen. The employee mentioned that, at first, their usernames were the same as their passwords. After they required stronger passwords, some managers complained, so they 'compromised' by allowing blank passwords. The whistleblower said he discussed his concerns with management, but that it was like talking to a brick wall. In spite of the weak internal security, TJX now has a firm that scours the internet to find bad things posted about them, which is how they found the message and fired him for it. Too bad they don't appear to have hired anyone to beef up operational security or to convince people to use strong passwords."
Who is TJX and how can I avoid doing business with them, but then I realized they were TJ Maxx and Marshall's and I don't do business with them anyways.
"I am the king of the Romans, and am superior to rules of grammar!"
-Sigismund, Holy Roman Emperor (1368-1437)
This was a server at one store, not the TJX headquarters where the data is kept.
"So last August, Benson took to Sla.ckers.org, a website dedicated to web application security, and began anonymously reporting the shoddy practices in this user forum."
Here's the TJX web site [warning: Flash], where you'll learn that they are TJMaxx, Winners, Marshalls, HomeSense, HomeGoods, TKMaxx, AJWright, and Bob's Stores. You can also read a nice letter from the TJX president and CEO describing how they have "...worked diligently with some of the world's best computer security firms to further enhance our computer security."
Blank passwords. Wow. No bad guys would ever try that. Disclosing that policy would really compromise security, wouldn't it?
The whistleblower protection laws in the USA protect an employee from termination for reporting the employer acting illegally. Shoddy security may be stupid but I don't know if it's illegal or not. Also, the employee needs to be reporting to the proper authority, not a random Internet forum.
"People that quote themselves in their signatures bother me" - athakur999