Earlier quoted context omitted.
"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…
>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud. Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal. Aka, not this: http://i.imgur.com/a7S95nG.jpg
Equifax security freeze PINs are the timestamp of when you request the freeze
101–110 of 193 posts
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#102Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.
How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#103Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.
How does Equifax, a private company, have the rights to access my personal data in the first place? Who exactly is giving it to them without my explicit consent, and why?
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#104Earlier quoted context omitted.
"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…
>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud. Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal. Aka, not this: http://i.imgur.com/a7S95nG.jpg
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#105It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?
"Critical systems" developers would need astronomically expensive insurance to even exist, and therefore prohibitively high salaries.
I personally believe there should be some measure of a corporate death penalty to emphasize the responsibility involved though.
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#106Earlier quoted context omitted.
Someone probably read an article about how RNGs aren't truly random, and so decided timestamp (which never repeats!) was the right alternative.
Of course, two people who happen to request at the same time will get the same key anyway, so it doesn't even solve that problem.
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#107This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…
And in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. A…
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#108Earlier quoted context omitted.
"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…
Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#109Earlier quoted context omitted.
This sounds like blockchain could have application. But honestly, other countries do fine without them, IMO they should just be abolished.
A blockchain is public. You want everybody's credit public?
Re: Equifax security freeze PINs are the timestamp of when you request the freeze
#110Earlier quoted context omitted.
"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…
>Who exactly is responsible for unrecognized vulnerabilities? Everyone? No one? One dude who everyone sorta thought handled security stuff? It's as clear as mud. Security team with people who do it full time. Betting your security on the one dude who sorta did everything should be criminal. Aka, not this: http://i.imgur.com/a7S95nG.jpg
Here's a quote from Equifax's early release on the breach [0]:
Equifax said that, it had hired a cybersecurity firm to conduct a review to determine the scale of the invasion.
So, to your question, I'm going with "no one", at least internally.
It's beyond belief (well, not really anymore); but, not only do they not have security covered internally (criminal in itself), but they don't even appear to have a regularly engaged cybersecurity firm. They had to go out and hire one post facto.
[0] https://investor.equifax.com/news-and-events/news/2017/09-07...