Sept. 9, 2023, 1:50 p.m. | /u/FloorOk74

cybersecurity www.reddit.com

Hi everyone, thanks for taking the time to read.

I joined a small software company that sells CRM/Accounting software in early 2022 as a software developer and it recently came to my attention that in our client databases, we hold the SSNs of employees in plaintext.

I asked the senior engineer about it, and he said that the encryption on the MSQL server was sufficient and that I shouldn’t worry. I didn’t agree, voiced my concerns but nothing came of …

accounting accounting software attention client crm cybersecurity database databases developer employees engineer joined plaintext software software developer

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)