Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

91–100 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#91

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

Developers don't control budgets and deadlines at large companies, management does. So what does this "certified" individual do when he's given a project without resources allocated for proper security auditing? Does he intentionally get fired for refusing the assignment? That works if he has bountiful savings, no mortgage, no kids. Surely no unethical contracting company will pick up the job after he leaves...

> Developers don't control budgets and deadlines at large companies, management does.

True, but that's why good organizations almost always have technical people on the management team who advocate for the technical arm of the company and ensure that it is appropriately resourced.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#92
post #39

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud.

Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal.

Aka, not this: http://i.imgur.com/a7S95nG.jpg

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#93
post #57

Earlier quoted context omitted.

Developers don't control budgets and deadlines at large companies, management does. So what does this "certified" individual do when he's given a project without resources allocated for proper security auditing? Does he intentionally get fired for refusing the assignment? That works if he has bountiful savings, no mortgage, no kids. Surely no unethical contracting company will pick up the job after he leaves...

How does it work with lawyers or engineers?

They will simply refuse to do the work. It's better to lose a job, than to lose a license.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#94
post #57

Earlier quoted context omitted.

Developers don't control budgets and deadlines at large companies, management does. So what does this "certified" individual do when he's given a project without resources allocated for proper security auditing? Does he intentionally get fired for refusing the assignment? That works if he has bountiful savings, no mortgage, no kids. Surely no unethical contracting company will pick up the job after he leaves...

How does it work with lawyers or engineers?

Engineers say "no, we can't build it that way" and people respect it because they know that engineer: knows their work and has recourse through their professional society as well as government oversight agencies if undue management pressure compromises safety. I don't see it playing out the same way for most software teams.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#95

This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…

You're surprised that large companies are incompetent?

My experience has been that the main product of most companies is management politics. Actually shipping product is nearly irrelevant to everyone's daily activities. In some cases, people get punished for being competent.

One company I worked with made it clear they had no interest in listening to competent people. People were promoted for their ability to suck up to management. They got promoted when the projects they managed were delayed, buggy, and generally non-functional. Any competent engineer was summarily drummed out of the company for causing trouble.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#96

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

Like PCI compliance?

Ask people who've gone through that process how rigorous it is...

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#98
post #43

Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.

This sounds like blockchain could have application. But honestly, other countries do fine without them, IMO they should just be abolished.

A blockchain is public. You want everybody's credit public?

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#99
post #39

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

How does this work in civil engineering or construction in general. It is also a team based endeavor. The way I understand it only engineers or management needs to go through certification. Basically people who direct the project.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#100
post #96

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

Like PCI compliance? Ask people who've gone through that process how rigorous it is...

It's rigorous, but in all the wrong ways.

At $DAY_JOB our security falls into two buckets (1) PCI and (2) stuff that keeps us secure.

IDK if it's possible to have a widely accepted security standard that isn't checking nonsensical and out-of-date boxes.

Post reply on HN