Security expert says she helped a casino whose high-roller database was stolen through an Internet of Shit fish-tank thermometer

B Tier casinos are the worst when it comes to IT security. The company I work for has bid on a bunch of jobs for smaller casinos, and within weeks of submitting we usually get blasts of spam from numerous email addresses from that casino.I’m betting it’s because some of our employees contact cards have been added to a compromised Outlook. It’s like (anecdotal) clockwork. Maybe this was some big Las Vegas place and I’m projecting, but I kind of doubt it.

Not saying those casinos are tribal casinos, but it still makes me wonder: what is the status of infosec and data privacy law on tribal lands?

I really wish there were technical details like what was the device. How was is exposed to the internet? Did that Casino do something as mind-numbly stupid as to use UPNP on their routers?

Odds are, the company that maintains their aquariums checks the status remotely, so someone punched a hole in the firewall to the thermometer to let them do it. Once the hackers were in the thermometer, they could access everything on the LAN behind the firewall.

Ugh. First of all, Eagan is no security expert. She’s a marketing person installed by crony-ism as figurehead by Mike lynch’s invoke capital. The real story here is also how Mike lynch is secretly the real ceo of the company, but hiding due to the ridiculous scandal involving his sale of Autonomy to Hp.


