Careless engineer stored recovery codes in plaintext, got whole org pwned

Cautionary tale from the recent SonicWall attacks

Failing to encrypt sensitive data leaves you wide open to attack. During the recent SonicWall attack spree, intruders bypassed multi-factor authentication (MFA) in at least one case, because a user’s recovery codes were left sitting in a plaintext file on their desktop.…

This article has been indexed from The Register – Security

Read the original article: