Going through the configuration backup process for the Sophos Email Appliance and came across the following:
- Only backup option is FTP
- Does not require username and password
- Backup files are not encrypted
- Admin/Helpdesk passwords are stored in raw SHA-1
As a security company it would seem that this process would be a little more hardened...or at least follow the OWASP standards for protecting stored credentials...https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Password_Storage_Cheat_Sheet.md
Has anyone else been concerned with this process?
This thread was automatically locked due to age.