Worst thing I ever witnessed in IT in 20+ years

Posted by JohnWellPacked@reddit | sysadmin | View on Reddit | 313 comments

Had a call with an ERP provider recently. He does his little screen share, and we invite an AI note taker so we can show the demo to our colleagues afterward. Their owner shows a demo of Odoo in a demo instance, and then, in a series of questions from our side, he wants to show something on another instance and opens a Google Sheet (with about 100+ rows in total) and scrolls through the full file. The Google Sheet contained links to all dev, staging, and LIVE environments (all running on HTTP - no SSL! even on PROD!!), with the full ROOT password next to each row. Many instances from different clients are shared on the same server (same IP). So not only did he expose all of it live, but he also showed us that they have 0 idea about any security practices. A rogue employee or that Google Sheet getting compromised, and all of their instances are gone. You can imagine no backups, also. Had to share. Happy Monday.