by Serguey Shinder
During the warehouse implementation in 2021 the vendor's support team asked for read access to our order database so they could diagnose the sync failures we were having twice a week. It was a reasonable request and we were three weeks from go live. We created a database user, gave it read on eight tables, and sent the credentials to the consultant we had been working with every day for four months. He put them somewhere at his end. I never asked where.
We replaced that product in 2023. The contract ended, the integration was switched off, and the project was closed with a fairly thorough handover document that does not mention the database user anywhere.
An access review this summer found it. Still active, still with read on eight tables, and it had authenticated four hundred and six times in the previous twelve months from addresses in three countries. The tables it could read had grown since 2021, because tables do, and by then they carried seven years of orders with the names, delivery addresses and telephone numbers of a little over a hundred and ninety thousand customers.
I want to be careful about what we found, because we found no evidence of anything improper. We also had no way whatsoever to form a view. We did not know who was using it. The consultant we had trusted had left that firm years before, and the people signing in with his credential were employees of a company we no longer had any relationship with, doing something we had no visibility of, in support of a system we had decommissioned.
Our joiners and leavers process is excellent, and it is attached entirely to people we employ. Somebody hands in their notice, HR raises a ticket, and twenty eight accounts get disabled on their last afternoon. Access granted to an organisation has no equivalent event. A supplier does not leave. It stops being relevant, gradually, on a date nobody writes down, while its own staff turn over and its own wiki keeps the credential exactly where it was.
We found fourteen non employee credentials in total. Six belonged to companies we were no longer paying.
Everything of that kind now carries an expiry of ninety days at most, and renewing it requires a named person on our side to say in a sentence why it still needs to exist, which takes them under a minute and stops about a third of them each cycle. Where we can, a supplier no longer holds a credential at all. We open a session for them when they need one and close it afterwards.
The question I ask now is not who has access to this. It is whose resignation would end it, and if the answer is nobody's, then nothing will.
– Serguey Asael Shinder
Leave a Reply