Earlier quoted context omitted.
maybe there was no way to save and transfer the pin from one place of the system to another, and the only way to do it is to guess on the other side by timestamp. pretty hacky implementation but oh well
Hash with a secret key (a pepper) solves that. Heck, hashing with a salt or even just plain hashing would be miles better than this.
Equifax security freeze PINs are the timestamp of when you request the freeze
41–50 of 193 posts
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#42Earlier quoted context omitted.
> are not Engineering/Tech companies Which means each and every line of code was written by the lowest bidder.
Or CEO/CTO's buddy's company
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#43Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#44Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#45If you develop in-house software, you ARE A SOFTWARE COMPANY, whether you want to be or not.
Amazing how this good old boy network still thinks like it's 1970.
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#46It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?
I may agree, but Equifax is by no reasonable definition "a critical system".
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#47Earlier quoted context omitted.
Developers don't control budgets and deadlines at large companies, management does. So what does this "certified" individual do when he's given a project without resources allocated for proper security auditing? Does he intentionally get fired for refusing the assignment? That works if he has bountiful savings, no mortgage, no kids. Surely no unethical contracting company will pick up the job after he leaves...
If only there were more software jobs out there, then they wouldn't be hemmed in so intractably.
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#48It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?
"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#49Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.
> are not Engineering/Tech companies Which means each and every line of code was written by the lowest bidder.
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#50Anyone else confirmed this? Don't know who Tony is, usually like more sources that a tweet.