Accenture pentest gaffe: consultants flag HTTPS-protected passwords as plaintext finding
nptacek · x · 2026-09-19
Security researcher IceSolst recounts an on-site anecdote: Accenture consultants presenting a pentest readout flagged "passwords stored in plaintext" — a request the client observed was seen over HTTPS inside Burp Suite. The consultants' fallback justification ("if someone breaks HTTPS the password leaks, so it should be encrypted") became a widely shared joke about the technical depth of big-consultancy security work.
More from Fun
- AI claims to solve the Riemann Hypothesis, only 'checked the vibes' — burny_tech · 2026-09-19
- Grady Booch: 'AI' was coined almost a decade before 'software engineering' — Grady_Booch · 2026-09-19
- Kid claims she spots AI images by their 'AIish eyes', sparking awe online — justalexoki · 2026-09-19
- X Exec Nikita Bier Jokes He Charges $500/Minute on Intro as Tweet Blows Up — nikitabier · 2026-09-19
- Tech Reporter Kylie Robison Celebrates One Year Since Being Fired — kyliebytes · 2026-09-19
- Mortgage $3,500, Grok Tokens $4,000: Nikita Bier's Elon-Linked Budget Woes — nikitabier · 2026-09-19