TOLOGIX - ISLG Maintenance

Project dealing with all ongoing maintenance of the current ISLG application (www.investorstatelawguide.com and dev.investorstatelawguide.com).

Problem with Research Reports in Notepad - HIGH PRIORITY

Assigned to
Harsh Parikh, Tech Lead at DevIT Harsh P. Jitesh Dhuravala, DevIT Jitesh D. Liam Murphy-Burke, Strategic Account Manager at Tologix Liam M.
Notes
Further to the video below, we're experiencing an issue where users are getting the wrong Research Report when they download the topic from the Notepad Feature within the existing application. Please ensure this is resolved as soon as possible. 

Also, please explain how this happened. These are supposed to be encrypted, confidential reports that are only accessible to users through their account on the subscriber site. The fact that another user's report is getting generated by another user is extremely concerning, and we need to be certain this can never happen again (both within the existing and new applications).

Thanks,

Morgan


Comments & Events

Harsh Parikh, Tech Lead at DevIT
Hi Morgan Maguire, CEO Morgan and Liam Murphy-Burke, Strategic Account Manager at Tologix Liam ,

We caught the issues. The issue actually occurred due to Permission on MS Word Identity tab . When Carbon 60 remove the Old Anil's user from server that time they didn't replace the new user on MS Office Identity tab.

Hence, When user was going to download word research notepad file the permission was incorrect application was not able to generate new word file and fetch the last Research notepad word file from server's folder.

We have set new user & password (Enterprise/harsh.parikh) on MSWord identity permission tab and now it is working fine.

Here, I have attached screenshot for your reference.

Morgan Maguire, CEO
OK. Thanks for getting to the bottom of this Harsh Parikh, Tech Lead at DevIT Harsh .

Should I report this back to Carbon60? I want to understand what failed in our systems, and what actions we can take to prevent this from happening again in the future. 

As I mentioned, it's extremely important that we avoid this from ever happening again. I'd also like to use this as an opportunity to asses our protocols for protecting confidential user data that is saved within the applications. For example, what encryption protocols are we putting in place for data saved by users in the new application (e.g., session tracking, notepad feature, notification and documents comparison)?

Thanks,

Morgan
Harsh Parikh, Tech Lead at DevIT
Yaa Morgan Maguire, CEO Morgan ​.. you can suggest carbon 60 to let us know when this kind of situation occured. like on which instances the old user is associated.

Regarding, data encryption we always saved ids on databse and all our new url in encrypted format for all tool (Document comparision, research notepad etc..)
Morgan Maguire, CEO
Sounds good, Harsh Parikh, Tech Lead at DevIT Harsh . Should I request that they audit and determine if any other account are under Anil's name then?

Ok. Great. Thanks good to hear, Harsh Parikh, Tech Lead at DevIT Harsh . Regarding the data encryption keys and tokens, how are these stored and how are they accessed? 

Morgan
Harsh Parikh, Tech Lead at DevIT
Hi Morgan Maguire, CEO Morgan ​,

The data stored in id format and when they are accessing in our application then we are  encrypted that ids with secure algorithm with key.

Yaa.. you can ask to carbon 60 for which instances still anil user is associated.
Morgan Maguire, CEO
Morgan Maguire completed this to-do.