Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
TJX employee fired for exposing shoddy security
Dan Goodin, The Register 2008-05-27

TJX Companies, the mammoth U.S. retailer whose substandard security led to the world's biggest credit card heist, has fired an employee after he left posts in an online forum that made disturbing claims about security practices at the store where he worked.

Comments Mode:
Rock and a hard place... 2008-05-28
Kohl (1 replies)
Re: Rock and a hard place... 2008-11-09
Anonymous
Self interest? 2008-05-29
Anonymous
TJX employee fired for exposing shoddy security 2008-12-04
Anonymous
Having been in a somewhat similar situation AND responsible for InfoSec and Compliance (minus the firing) at one of the "Big 4" card companies who mandates the PCI compliance, it saddens me that large risks are swept under the carpet. Knowing what I do, having witnessed several CISSP/CISM/CISA-certified personnel turning a blind eye or simply shrug for the sake of a year-end bonus makes me want to vomit. Ethics? When tied to a dollar amount, you'd be amazed how they fly out the window. Risk seems to magically disappear! The customers no longer matter.

It saddens me that there is a lack of interest or leadership within TJX to have overlooked the concerns of an employee with "security 101" quick fixes; especially after the largest breach.

But this is nothing new. Is it?

Perhaps with the governmental administrative changes forthcoming, the dawn of a new Security area will surface. We can only hope.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11520/35296#35296







 

Privacy Statement
Copyright 2009, SecurityFocus