# dotnet & # powershell developer, runner, ex-pat Hoosier now living in the mountains of VA, supporter of # LFC ⚽️ # IUBB 🏀 # USMNT ⚽️ # USWNT ⚽️ Hashtag disciplined: you should, but you don't have to like EVERYTHING I do, so go on ahead and mute a hashtag. Searchable via Tootfinder https://www. tootfinder.ch/
# dotnet & # powershell developer, runner, ex-pat Hoosier now living in the mountains of VA, supporter of # LFC ⚽️ # IUBB 🏀 # USMNT ⚽️ # USWNT ⚽️ Hashtag disciplined: you should, but you don't have to like EVERYTHING I do, so go on ahead and mute a hashtag. Searchable via Tootfinder https://www. tootfinder.ch/
This makes me so twitchy. This patient status page, served over HTTP and not HTTPS, has the credentials as query parameters. Such shocking op sec in a healthcare environment, both as a deployed solution and a commercial product.
We know the username, have a head start on the password (with a good idea of the encoding), and the presence of a “user privileges” tab [not pictured] suggests the account has more permissions than necessary.
Dear god. 🤦