When I'm working on a client web site, and the budget extends to a test server, I always lock access to the test server down to the IP numbers of just the client and myself. For obvious reasons, you don't want curious bystanders to accidentally fall over your test bed. Although I did once have a sub-contractor who on several occasions posted test server URLs in programming discussion forums seeking advice on code matters. Put a stop to that pretty darn quick.
Apparently the IT guys at the Florida Agency for Workforce Innovation forgot to hide their test server - and made available a couple of hundred thousand names and social security numbers, before the bean counters over at the Department of Revenue happened to notice.
It was, of course, a 'glitch'.









Comments