Live data from Hacker News

Hackers who broke into Equifax exploited a flaw in open-source server software

qz.com

21–30 of 84 posts

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#21
post #13

Earlier quoted context omitted.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.

> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.

Which way to the frog sauna?

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#22
post #13

Earlier quoted context omitted.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.

> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.

So if someone takes this data and just keeps the whole dataset exposed publicly on a tor site, is that pretty much the end of data breaches?

Like, some random website: "we just got hacked, all you pii was taken, but don't worry nothing thats not already available in that public database"

other than new credit card #'s it'd be basically pointless right?

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#23

Earlier quoted context omitted.

Equifax discovered the hack on July 29, more than a month before this vulnerability was discovered.

A month before this vulnerability was discovered by these specific security researchers .

A month before it was _disclosed_ by these researchers.

Given the magnitude of this hack, it is entirely possible they embargoed it for a while.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#24
post #22
post #13

Earlier quoted context omitted.

> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.

So if someone takes this data and just keeps the whole dataset exposed publicly on a tor site, is that pretty much the end of data breaches? Like, some random website: "we just got hacked, all you pii was taken, but don't worry nothing thats not already available in that public database" other than new credit card #'s it'd be basically pointless right?

Well... no.

Everybody on that list will change their CC and life carries on until the next breach.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#25

This is based on a report from Baird Equity Research. Some key items from that report: * "Our understanding is data retained by EFX primarily generated through consumer interactions was breached via the Apache Struts flaw (i.e., core databases not believed to have been breached)." * "Key EFX databases are not known to have been breached as part of the incident, including the consumer credit file, TWN, NCTUE, IXI, or…

I find it curious how one can implant code like this into existing codebases. It takes us a while to code review and deploy, and when we deploy we overwrite what's already on production

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#26

Earlier quoted context omitted.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and p…

Sure, if you don't have physical security, you have no security. Goes without saying.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#27

Earlier quoted context omitted.

If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and p…

Sure, if you don't have physical security, you have no security. Goes without saying.

Unfortunately ~nobody does. The effectiveness of red teams was one of the most surprising aspects of working in security. The most common way to break into someplace was to pose as a construction worker: http://i.imgur.com/ZjnGmZ5.png

If you're dressed as one of them, you can go wherever you want and people rarely ask questions. Another approach is to pose as an interviewee. That's how you get into the building, but beyond that you never actually talk to anyone so nobody is suspicious. People generally don't care when someone is walking around the halls dressed up in a suit.

One of my coworkers was involved in dozens of red teams and he got caught a grand total of one time. Every other time he was able to acquire an IP address, take a picture of himself sitting in the exec's chair, swipe a file out of the server room, or whatever the customer wanted.

Re: Hackers who broke into Equifax exploited a flaw in open-source server software

#28
post #7
post #6

Earlier quoted context omitted.

I just hope the EFX breach used an older exploit and not a zero-day. That may have some influence on their perceived liability.

Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.

I despise the existence of the credit reporting bureaus and would love to see one of them caught with their pants down for a breach that was entirely preventable (well, at least through the vector that was used). If they failed to patch a known vulnerability, and that caused the breach, likely they'll be on the hook for a larger payout once settlement time comes.
Post reply on HN