Live data from Hacker News

Equifax Faces Multibillion-Dollar Lawsuit Over Hack

bloomberg.com

281–290 of 670 posts

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#281

How likely is it that Equifax will face any real trouble from this breach? Will this be one of the first cases where security negligence causes real harm to a company? Or will it turn out to be another slap on the wrist?

Slap on the wrist, guaranteed: - potentially every one of the 143M people are going to have some sort of trouble - WORST CASE equifax shuts down, but that doesn't matter. too late. - if everyone was to win a lawsuit for everything equifax is worth, they'd get maybe $100 minus lawyer fees. And worse, now we have a financial system dependent on 2 companies. Making a 3rd isn't an easy matter. ::shrug::

EquiFax declares bankruptcy, re-orgs and rebrands.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#282
post #260

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

No amount of governmental regulations can solve the current date breach trends. Even government's own intel agencies got hacked too. No organization is immune to data breaches. It's a matter of time and effort. A lot of us here are engineers and coders. It's our responsibility to design better architecture, security conscious protocols and write securer softwares. And it's up to all of us (regardless which country yo…

I think it's a fruitless effort to try and secure all of the data in the world. Our data is lying in too many places, the databases holding them are too complex, as another user stated, a breach is really just about money and time. Our systems are too complex to merely increase security standards.

I think we can significantly improve the situation though with increased data collection laws, and then also more cryptography. Equifax shouldn't have all that data in the first place. A lot of the reasons that companies need data (besides machine learning) can be covered with cryptographic arguments that exclude the data itself.

For example, cryptography exists that would allow me to use my driver's license to prove to you that I am over 21, without ever actually showing you my real birthday or name. You could be 100% convinced that I both have a valid ID and that ID indicates that I am over 21 without learning anything more than those two facts.

If you can do things like that, you can make it illegal for companies to hold more sensitive information. If there's a big data breach that loses sensitive information, the company at fault can be charged for illegal data collection.

I know it's a big step from the data driven world we currently live in, but I think it's the only way to avoid a scenario where pretty much all details of every person's life (including politicians, secret agents, military figures) are public knowledge. We're just collecting far too much data, putting it in far too many places, and it's technologically infeasible to protect all of that.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#283

How likely is it that Equifax will face any real trouble from this breach? Will this be one of the first cases where security negligence causes real harm to a company? Or will it turn out to be another slap on the wrist?

143 million people, or essentially every US citizen over 18 (give or take a few million.) It most likely includes Senators, Congressman, Donald Trump etc etc. So, yeah, a lot of people will be inconvenienced and pissed off, ad for a very good reason.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#284

Earlier quoted context omitted.

This is the genius of small-claims court. Equifax has to either send a representative (which would cost them more than $1000), or they lose by default. You don't actually have to prove anything.

It really isn't genius at all. At least in my state, either party can object to the small claims status by simply sending a letter. Then it moves over to normal court with normal lawyers. Already you are out the small claims filing fee (yes, you have to pay the court to even bring a small claims case). Once in normal court, you would need to hire a lawyer, and they would just find some local representation. At this p…

That is an incredibly pro-corporate anti-individual jurisdiction. Where is this?

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#285
post #269
post #263

Earlier quoted context omitted.

Sure, in a fantasy land. If you where to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. The very fact that all this data was accessed from their public site is very troubling. What's the chances this is a basic SQL injection issue? What's the chances they didn't invest in security at all?

> If you where (sic) to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. What makes you think lack of investment in IT & security is the main reason they get hacked? Vice versa, NSA has virtually unlimited (let's just say unlimited means tens of billion dollars) budget invested in IT and security. They have the top resources there too. Do…

Certainly a lack of mental investment. The NSA and these credit agencies are not a comparison, as their jobs are quite different. If nothing else, the NSA has to be connected to public networks to do their covert operations. Not so with a "credit rating agency". They should not be on a public network at all. Before the Internet, they were not, they were on private leased lines.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#286
post #269
post #263

Earlier quoted context omitted.

Sure, in a fantasy land. If you where to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. The very fact that all this data was accessed from their public site is very troubling. What's the chances this is a basic SQL injection issue? What's the chances they didn't invest in security at all?

> If you where (sic) to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. What makes you think lack of investment in IT & security is the main reason they get hacked? Vice versa, NSA has virtually unlimited (let's just say unlimited means tens of billion dollars) budget invested in IT and security. They have the top resources there too. Do…

Correct me if I'm wrong, but the NSA leaks have all been the result of internal employees leaking outward, rather than outside people reaching inward where they shouldn't. That's a meaningful distinction, IMO. They call for two completely different types of defense.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#287

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

If there was insider trading on the breach information, they'll be in the slammer soon enough.

It would be pretty stupid, considering how easy it would be to get caught, and to avoid a mere ~14% decline on your share value? Yes, people can be stupid and greedy. I guess we'll see if this applies to these execs.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#288

How likely is it that Equifax will face any real trouble from this breach? Will this be one of the first cases where security negligence causes real harm to a company? Or will it turn out to be another slap on the wrist?

143 million people, or essentially every US citizen over 18 (give or take a few million.) It most likely includes Senators, Congressman, Donald Trump etc etc. So, yeah, a lot of people will be inconvenienced and pissed off, ad for a very good reason.

Senators, congressmen and Donald Trump himself all had their data previously leaked at least once before. Nothing changed as a result.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#289
post #9

>In the complaint filed in Portland, Ore., federal court, users alleged Equifax was negligent in failing to protect consumer data, choosing to save money instead of spending on technical safeguards that could have stopped the attack. Doesn't "users" imply that we had a choice in the matter? As if we're Equifax's customers? I feel more like we're victims in this case.

Got an email from my Dad today:

"I checked myself, my wife, you and your brother. To the best of my knowledge none of us have Equifax accounts, but it says they probably got our address & driver's license for all four of us.

I don't want to waste money on LifeLock. What can I do? Just watch my accounts?"

Is Visa, MasterCard, etc. at least partially to blame here for picking a bad solution? My personal ties are not with Equifax, I have no direct means as a consumer to express dissatisfaction. Can I sue Visa? They are they ones (I presume anyway) who did the actual information collection from me, and then it was mishandled.

We need more tools for dealing with data breaches. Things aren't slowing down, and they aren't going to unless something big changes.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#290
post #260

So let me get this right, this company collects credit information and someone hacked into their web server and stole highly sensitive information about most of the adult american population. Then the executives sold their stock a day before they announced the hack to the public. Besides the troubling fact that you still use social security and credit card numbers as any form of reliable authentication, how aren't th…

No amount of governmental regulations can solve the current date breach trends. Even government's own intel agencies got hacked too. No organization is immune to data breaches. It's a matter of time and effort. A lot of us here are engineers and coders. It's our responsibility to design better architecture, security conscious protocols and write securer softwares. And it's up to all of us (regardless which country yo…

"No amount of governmental regulations can solve the current date breach trends." I'm sorry, but that is just flat out false. That type of thinking is just bizarre to me. It would make a gargantuan difference. Hold executives personally accountable, with whistle blower laws protecting the developers who identify weak security. It would change the freaking world over night.
Post reply on HN