3/20/2026 at 8:54:41 AM
Reminds me of the famous "Our security auditor is an idiot. How do I give him the information he wants? [1][1] https://serverfault.com/questions/293217/our-security-audito...
by sam_lowry_
3/20/2026 at 10:06:30 AM
That is crazier than any old dailywtf stories, and that site felt like everyone tried to one-up each other.by zvqcMMV6Zcr
3/20/2026 at 9:52:35 AM
Is there some part of PCI auditing requirements that is getting misinterpreted by some auditors to demand this? Though in my experience with standards like this what auditors want to see and what the standards say often have only loose overlap anyhow.by rcxdude
3/20/2026 at 1:53:33 PM
It's pretty counterintuitive from an auditing perspective. If the PCI standards require server racks to be painted red, it's entirely normal for an auditor to ask to see them, and very suspicious for you to say that they're in an encrypted box where nobody can check if they're red or not. I don't mean to excuse it, but I can understand how the error happens.by SpicyLemonZest
3/20/2026 at 2:13:05 PM
This is true. Maybe it's someone seeing a requirement like "all passwords must conform to these rules" and deciding that it means they need to check them directly, instead of looking at the systems that enforce that constraint.by rcxdude
3/20/2026 at 12:24:15 PM
Right until the end I thought the guy was doing a social engineering penetration test, checking whether he could brow beat the server admins into bending over backwards to reveal this information.by samus