Live data from Hacker News

Equifax Faces Multibillion-Dollar Lawsuit Over Hack

bloomberg.com

591–600 of 670 posts

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#591

Earlier quoted context omitted.

In principle that's true... In reality 1. You can be shot by a cop even if you do not pose a real threat (they just need to claim they though you might have a gun, simple) 2. People are routinely kept in jail for unreasonably long time because their families cannot afford bail often on things charges are dropped for later 3. Ever hear of civil forfeiture? The whole thing is a nice story that we love to repeat to each…

> Ever hear of civil forfeiture? Yes, a process in which the government has to prove to the same standard of evidence as someone suing you. That is due process.

> Yes, a process in which the government has to prove to the same standard of evidence as someone suing you.

That's not quite true. They don't make a claim against _you_. They make a claim against the property.

So, it's the same level of evidence and adversarial hearings as someone suing $1,000. This is not due process. It's a farce.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#592

Earlier quoted context omitted.

True, but in the US you can not really sue for possible harms. You can only sue for actual harms which can be remedied by the court. Leaking your information isn't a harm the court can remedy. Abuse of the leaked information is a harm the court can remedy.

I don’t think that’s a generally accepted legal standard. It seems similar to saying that Edward Snowden and Chelsea Manning only released information, which the courts can’t remedy. If anything bad should happen due to that leak, then the courts can remedy that in the case of the people who committed those acts. The government is clearly of the opinion that they can and should prosecute people for leaking informatio…

The State prosecuting someone for a crime is not the same thing as a private individual suing another individual for a tort. Basically everything is different: different rules of procedure, different rules of evidence, different standard of proof required, etc. etc.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#593

Earlier quoted context omitted.

I don't really care where the money goes. I think that having one catastrophic event (huge lawsuits or fines leading to bankruptcy) for a corporate entity because of negligent security measures may lead other board rooms to move security measures up their priority list.

It may cause security to get tightened to prevent these types of incidents, but I doubt that it will improve security culture. Going forward, we would theoretically be protected from a breach of this type in other companies, but proper security is a continually moving target. New methods exploits are discovered all the time. That's what I'm worried about - are they going to be proactive in securely protecting informa…

Business as usual, and you know it.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#594

To be honest, I feel bad for the engineering team at Equifax. The vulnerability that compromised their system was a bug in an open-source Java library, Apache Struts, and security researchers only noticed it a few days ago. It seems that the Equifax team had very little time to react and update their software. In some sense, I feel that more blame should be placed on the engineers who built the highly popular open-so…

I would have expected the data to be encrypted at rest. I am not sure why that was not the case.

It doesnt help if that data is being accessed all the time by applications. You just have to break into one application in order to exfil the data or to get the decryption method along with the encrypted data.

'Encryption at rest' only works for data that is not actively used, like backups or if a physical storage device is stolen.

A better additional safeguard is to have quotas and alarms in place for data access. Is data being accessed sequentially in a application environment where data is usually accessed randomly? Is data access bound to individual credentials and do indivudals access more data than usual?

I think, there is actually potential for new database products or addons, which can reduce the impact of breaches in the vicinity of these 'core databases'.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#595

Earlier quoted context omitted.

IANAL, but I think you'd find it virtually impossible to show $1000 of direct, material damages as a result of having your information leaked[0] and to the best of my knowledge this is the only sort of claim that small claims courts allow - I believe they do not allow punitive damages, nor theoretical ones. 0: Unless your info is actually used in a way that harms you, and you can prove that it was a result of this, b…

Is it really so hard? Cost of a service like Equifax's own TrustedID or LifeLocks is over $100/year. Seems you could easily argue that you'd have to subscribe to said service for the next decade to guarantee your credit and identity aren't stolen? (and I would think refusing to accept Equifax's "coupon" for TrustedID would be a similarly easy argument to make)

> to guarantee your credit and identity aren't stolen?

there's no right to not having your identity not stolen tho. By this logic, shouldn't you _always_ have the identity-theft prevention service paid for already, regardless of what happened to equifax?

I think you'd have to show _actual_ identity theft occurring with your name to claim damages.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#596

Earlier quoted context omitted.

>And while it's almost inevitable that discussions about class action suits will involve complaints about the lawyers fees, that's not really fair. Of course it's fair. It's not like the members of the class get to shop around for cheaper lawyers. The class gets shit either way, they just have to decide if they hate the company more than the lawyers that charge the obscene percentages. And you can't make any kind of…

Attorneys' fees in a class action have to be approved by the court, and for large class actions the percentage fee tends to be lower than what a privately-retained lawyer would receive. The privately-retained lawyers in NTP's lawsuit against Blackberry got an approximately 1/3 payout of a $600 million settlement. 20-33% is quite typical in a pure contingency situation. Most court-approved fee awards in class actions…

Still, class attorneis will settle faster and for less. That often drives total comp and remedies a order of magnitude more than fees percents, like in the recent antipoaching litigation.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#597

To be honest, I feel bad for the engineering team at Equifax. The vulnerability that compromised their system was a bug in an open-source Java library, Apache Struts, and security researchers only noticed it a few days ago. It seems that the Equifax team had very little time to react and update their software. In some sense, I feel that more blame should be placed on the engineers who built the highly popular open-so…

There is some debate as to which Struts exploit was used. If it was the one from Sept, 2017 then you make a valid argument. However, if the exploit used was years old then the fault clearly lies on Equifax for not keeping their servers up to date. Also, didn't the Equifax breach happen in May, 2017? If so, I fail to see how the Sept, 2017 exploit plays into this unless it was in the wild months before it was publishe…

[deleted]

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#598
> Others expressed frustration that three senior executives sold about $1.8 million in stock in the days following the discovery of the hack. A spokeswoman for Equifax said the men “had no knowledge that an intrusion had occurred at the time.”

Wait, what? Isn't this a blatant example of insider trading? Moreover connected to a problem they are responsible for?. Do they seem to be really that stupid or is there a chance that they could get away with that in the end?

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#599

Earlier quoted context omitted.

Replacement credit cards are not the issue. Whoever has this data has the complete dataset to open new credit cards in your name, buy a car in your name, get plastic surgery in your name, etc. The hassle will be convincing all those companies that you do not in fact owe them thousands, and there is no automatic protections for these types of harms.

Even worse, is if you don't immediately notice a new account on your credit report, that then goes to collections. -_- 10 years later and I still get threatening calls from the shadiest of shady "collection agencies"

must be terrifying. sorry about that. but free money is free money.

Re: Equifax Faces Multibillion-Dollar Lawsuit Over Hack

#600

To be honest, I feel bad for the engineering team at Equifax. The vulnerability that compromised their system was a bug in an open-source Java library, Apache Struts, and security researchers only noticed it a few days ago. It seems that the Equifax team had very little time to react and update their software. In some sense, I feel that more blame should be placed on the engineers who built the highly popular open-so…

> In some sense, I feel that more blame should be placed on the engineers who built the highly popular open-source software, not the Equifax team.

I completely disagree. It is open-source for a reason. If you find a bug in it, fix it and everybody wins. Otherwise, nobody would ever publish any code/software because you would get sued if you did any mistake. On top of that, the software is free. So you basically want to blame some group which gave you something for free which you used to make big money and expect to also sue them for consequences if they made a mistake.

I also feel bad for the engineering team at Equifax. But on the other hand, you have to take into account that any software you employ could have a security flaw in it. That is why you should have additional means to protect it and no single point of failure. And this is especially true if your whole business depends on that data!

edit: spell check

Post reply on HN