HN Hall of Fame Weekly email

How do I give our security auditor the information he wants? (2011)

serverfault.com Essays & writing Forum discussions Security & privacy Candidate
Screenshot of serverfault.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 7 calendar years, with breakout response in 3 of them.

submissions
13
submitters
13
observed span
2011–2026
peak thread · 83 comments
204 pts
latest 20+ return · 2023-06-18
178 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

Birmingham? I think I know this guy - we have a client based there and are three years into a war with their PCI auditor, who are dangerously incompetent. They were adamant that we should be able to decrypt PANs (credit card numbers) - we still haven't complied, as we quite deliberately don't store them and just transit them. It's not a phishing scam, this is pretty much state of the art in the UK - and try being a…

Definitely seems less like a auditor (I believe asking for some of that is flat out illegal) and more like a hacker posing as a auditor, trying to get passwords/creditcard #'s.

The last time this got discussed, I thought the consensus was he was trolling -- the point being the correct answer is to explain why you don't have these (technical controls, hashing of passwords, etc.). The other reason would have been if he wanted login access to servers to validate configs himself, but there are much better ways to accomplish that (I'd be very reluctant to give an auditor anything but read-only access to any production infrastructure, but it is…

rdl·70-point thread·

My first thought was red team. Anyone that is capable of complying to the request is in breach. Ctrl-F "red team" found nothing. But then I read the answers and apparently a couple of them had the same idea. Not sure why it's not the most upvoted option, it seems like the only one that is is not self refuting, as the sincere version of those hypothetical businesses would starve from terminal stupidity... Perhaps my reasoning is wrong?

futune·8-point thread·

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
3

100+ points or 50+ comments

Total points
688

reference only — not used in Hall rules or ranking

Total comments
201

reference only — not used in Hall rules or ranking

Every submission