tomspark wrote:
this is why you never put sensitive info in support tickets that you wouldn't want leaked. companies need to start treating these systems like they're already compromised — because increasingly they are. bpo providers are basically honeypots at this point, zero incentive for them to maintain security when they're managing tickets for a hundred different clients. the real question is why support tickets even need to contain passwords, api keys, or anything that would actually matter if stolen.