Reply to post: Encryption

TalkTalk incident management: A timeline

Richard Wharram

Encryption

Encryption might not have made any difference. If they just used SQL to query the data out of the database then it doesn't matter if it was encrypted at rest or if the channels the data travelled over were encrypted.

Allowing SQL injection usually means you developed your website in an old framework that didn't block it by default (like classic ASP or early versions of RoR) or that your devs over-rode the defaults to make their code easier. Also that you didn't run any number of automated pen-test tools against the site. Or that you ignored the results if you did.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon