> wall.txt
General archetypes, not call-outs. No specific companies or incidents named —
if you recognize your org here, that's a coincidence and also maybe a hint.
Shame
- "We take security seriously" — sent 3 days after the breach, in Comic Sans
- Password requirements: 8 characters, one number, no special characters, must not exceed the length of a tweet
- "Please reply with your password to verify your identity" — from IT, apparently
- Storing passwords in plaintext, but the login page has a nice padlock icon so it's fine
- The admin panel is at /admin and the password is admin123, but at least it's not admin
- Rotating a leaked API key by... appending the number 2 to it
Fame
- Publishing a real, dated postmortem instead of a vague "we're aware of an issue"
- Running a bug bounty and actually paying out on time
- Security headers that get an A+ without a single inline script exception
- A warrant canary that's still chirping and actually gets updated
- Rate-limiting login attempts instead of relying on hope
- A PGP key that's actually reachable, current, and matches the fingerprint printed elsewhere
< back