DEV Community

Serguey Shinder
Serguey Shinder

Posted on

The Account You Forgot to Disable Is the Door You Left Open

The scariest thing I ever found during a security review was not a clever exploit or a zero-day. It was a spreadsheet. Someone had exported the list of active accounts against the list of current employees, and roughly thirty logins belonged to people who no longer worked there. One of them was a contractor whose engagement had ended fourteen months earlier. His credentials still worked. His VPN access still worked. Nobody had touched that account since the day he left, because leaving is quiet, and quiet things do not generate tickets.

We spend enormous energy defending the front door against attackers who have to guess their way in, and almost none on the doors we handed out ourselves and never asked back. A dormant account with valid credentials is the single friendliest thing you can offer an intruder. There is no password to crack, no firewall to slip past. Someone was trusted, that trust was written down in an access list, and then the person changed but the list did not. The permission outlived the relationship.

What makes these accounts so dangerous is precisely that nobody is watching them. An active employee notices if their login behaves strangely. A departed one never will. So when an old set of credentials leaks in some unrelated breach and an attacker tries them against your systems, the login succeeds silently, and the only person who could have raised the alarm has been gone for a year. The account works perfectly, on behalf of exactly the wrong person.

The fix is not glamorous, which is why it rarely gets funded until after something goes wrong. Offboarding has to be as disciplined as onboarding, tied to the same trigger, run by the same reflex. When someone leaves, their access should die that same day, automatically, not whenever a manager remembers to file a request weeks later. And every quarter you should reconcile who has access against who is actually employed, because drift is silent and constant.

Access is not something you grant once and forget. It is a standing liability that has to be revoked as deliberately as it was given. Every credential you issue is a door, and a door nobody remembers to lock is not a smaller risk than one left wide open. It is the same risk, just harder to notice.

– Serguey Shinder

Top comments (0)