Are all security consultants useless?
Posted by ArticleGlad9497@reddit | sysadmin | View on Reddit | 150 comments
I can't be the only SysAdmin getting increasingly more and more fed up with having to deal with security consultants who don't have a clue what they're doing can I?
It probably doesn't help that their standard pay seems to be much higher and yet their ability to apply knowledge sensibly is completely lacking.
I have to deal with several NHS trusts and so granted they're probably bottom of the barrel security consultants be even so, it's infuriating.
Last week one of them wrote to us as they'd pentested the service we host for them and found several security headers were missing. I knew they were there so that was odd and also there should have been a number of other low scoring vulnerabilities that were missing.
First off I speak to the other admin, we've had no request to turn off or bypass their WAF so that would have hidden pretty much all the vulnerabilities but even more impressive I realised he had run the pentest using an external tool. As part of his initial security requirements for our product we blocked connectivity to the portal from everywhere other than 3 public IP addresses. So essentially he has pentested absolutely nothing...
I pointed this out to him and his response was that he will mark it as a false positive... And that we've passed the pentest....WTF!
As the SysAdmin I'm happy to get it off my plate but as a member of the UK public a part of me feels the need to raise this ineptitude within the trust because god knows what else this guy has signed off without having a clue what he is doing...
Please restore my faith and let me know there are some good ones somewhere....
150 Comments
Low_Researcher4042@reddit
a60v@reddit
Stonewalled9999@reddit
a60v@reddit
Stonewalled9999@reddit
Go_F1sh@reddit
Stonewalled9999@reddit
IamHydrogenMike@reddit
kaiveg@reddit
CallistaMouse@reddit
samtresler@reddit
tankerkiller125real@reddit
kuroimakina@reddit
Go_F1sh@reddit
SchizoidRainbow@reddit
Go_F1sh@reddit
-RFC__2549-@reddit
ArticleGlad9497@reddit (OP)
Lethalspartan76@reddit
DeathIsThePunchline@reddit
1996Primera@reddit
Go_F1sh@reddit
serverhorror@reddit
Dizzy_Bridge_794@reddit
TheLegendaryBeard@reddit
WorthPlease@reddit
Draoken@reddit
FlibblesHexEyes@reddit
ProfessionalWorkAcct@reddit
OgeFace@reddit
jaydizzleforshizzle@reddit
popegonzo@reddit
QuietGoliath@reddit
Zombie13a@reddit
dasreboot@reddit
phantomtofu@reddit
sysacc@reddit
ProfessionalWorkAcct@reddit
ArticleGlad9497@reddit (OP)
Then-Chef-623@reddit
Scary_Bus3363@reddit
tankerkiller125real@reddit
genscathe@reddit
TaiGlobal@reddit
Scary_Bus3363@reddit
SteveJEO@reddit
genscathe@reddit
MendaciousFerret@reddit
genscathe@reddit
MendaciousFerret@reddit
genscathe@reddit
MendaciousFerret@reddit
genscathe@reddit
Maro1947@reddit
NSFW_IT_Account@reddit
tankerkiller125real@reddit
aes_gcm@reddit
RikiWardOG@reddit
CluelessPentester@reddit
Craptcha@reddit
genscathe@reddit
gandraw@reddit
derpingthederps@reddit
ReflectedImage@reddit
accidentalciso@reddit
Fresh_Dog4602@reddit
Sir__Swish@reddit
VacantlyCloudy@reddit
VacantlyCloudy@reddit
rootsquasher@reddit
kerosene31@reddit
420GB@reddit
ElectroSpore@reddit
Check123ok@reddit
ElectroSpore@reddit
ArticleGlad9497@reddit (OP)
ElectroSpore@reddit
ClericDo@reddit
ElectroSpore@reddit
n0p_sled@reddit
ElectroSpore@reddit
m1stymem0ries@reddit
n0p_sled@reddit
cybergibbons@reddit
ClericDo@reddit
itishowitisanditbad@reddit
renderbender1@reddit
ArticleGlad9497@reddit (OP)
reegz@reddit
ElectroSpore@reddit
topinanbour-rex@reddit
reegz@reddit
ElectroSpore@reddit
Good_Amphibian_1318@reddit
sohcgt96@reddit
Perfect-Tek@reddit
sohcgt96@reddit
ArticleGlad9497@reddit (OP)
Good_Amphibian_1318@reddit
ArticleGlad9497@reddit (OP)
Good_Amphibian_1318@reddit
Good_Amphibian_1318@reddit
SteveJEO@reddit
Obi-Juan-K-Nobi@reddit
m1stymem0ries@reddit
Perfect-Tek@reddit
pc_jangkrik@reddit
kaiveg@reddit
Frothyleet@reddit
wideace99@reddit
ArticleGlad9497@reddit (OP)
TheGreatAutismo__@reddit
ArticleGlad9497@reddit (OP)
TheGreatAutismo__@reddit
CryktonVyr@reddit
kirksan@reddit
nv1t@reddit
ArticleGlad9497@reddit (OP)
PurpleFlerpy@reddit
cybergibbons@reddit
ArticleGlad9497@reddit (OP)
n0p_sled@reddit
ArticleGlad9497@reddit (OP)
n0p_sled@reddit
AncientWilliamTell@reddit
Kemaro@reddit
DharmaPolice@reddit
giovannimyles@reddit
PizzaUltra@reddit
MaxTheV@reddit
thortgot@reddit
ArticleGlad9497@reddit (OP)
B4rberblacksheep@reddit
whatsforsupa@reddit
Direct-Mongoose-7981@reddit
Layer7Admin@reddit
Pyrostasis@reddit
TheOhNoNotAgain@reddit
malikto44@reddit
PokeMeRunning@reddit
raip@reddit
RikiWardOG@reddit
tectail@reddit
Zombie13a@reddit
Gadgetman_1@reddit
ericjgriffin@reddit
TheBestHawksFan@reddit
Outside-After@reddit
ConfusionFront8006@reddit
Narrow_Victory1262@reddit