Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

121–130 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#121
post #85

Earlier quoted context omitted.

Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.

I agree in part, but I think there are a few things about this scenario that highlight the problems with software. First is its extreme mutability: you can endlessly patch it, and often have to when vulnerabilities or flaws are discovered. Unfortunately this tends to lower the bar for a first release. Second, if you want to be cost-effective you must leverage many existing components of mostly unknown providence and…

> First is its extreme mutability: you can endlessly patch it, and often have to when vulnerabilities or flaws are discovered.

Sometimes, instead of patching, the software should be decommissioned. Search in the news for planes which were grounded when serious flaws are found.

> Second, if you want to be cost-effective you must leverage many existing components of mostly unknown providence and quality.

There're different components for different kinds of requirements. You won't use components for two story buildings, to build a skyscraper.

> Finally the security aspect is extremely difficult because both the cost and risk of mounting an attack are extremely low.

If the risks are high, systems shouldn't be deployed. There's a reason we don't allow people to have machine guns for self defense.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#122
post #39

Earlier quoted context omitted.

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

The management who told the developers "we need this done by tomorrow, figure something out or it won't be good for you"

>The management who told the developers "we need this done by tomorrow, figure something out or it won't be good for you"

Imagine, that management tells their lawyers, we need to do it tomorrow, figure something out? Most likely, lawyers will either refuse to do the work, or will report the management to law enforcement.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#123

This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…

>purge their PII from a credit authority I can't see that happening if they do any kind of offsite back up and archiving. They will purge you from the current master, say they purged you, and you'll be none-the-wiser.

The best solution for this would be to enable similar data protection laws like the ones that will become active in 2018 in the EU.

A breach of this law would cost a company 2-4% of their revenue as a fine. Seeing how these big companies operate there would be a lot of breaches.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#124
post #85

Earlier quoted context omitted.

Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.

While I agree, how do you apply software engineering practices in a field where a good chunk of the workforce doesn't have formal computer science education?

The same way real engineers work: classroom training in formal engineering, followed by years of experience under an accredited engineer in the field. There is testing at each transition to weed out the skaters.

Software engineers don't need to be computer scientists, in the same way civil engineers don't need to be materials scientists.

There is a bootstrap process, and even in other industries not all engineers are PEs... but all projects are reviewed and stamped by PEs.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#125
post #19

Something worth taking into consideration is these companies are not Engineering/Tech companies at the core. They were probably born as paper-companies and digitized their operations later on. I am hoping for the day something and more appropriate for this age will make them irrelevant.

> I am hoping for the day something and more appropriate for this age will make them irrelevant. We have the technology to build vastly superior replacements right now. It's mostly network effect requirements that make this extremely challenging/slow to implement. An example of something we could do is cryptographically authenticated web-of-trust creditworthiness estimation, with techniques like proof of burn and sel…

I find technical discussions around this subject extremely fascinating but I'm a total noob in this space. Would you mind sharing any relevant links on the topics you mentioned?

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#126
post #12
post #6

Earlier quoted context omitted.

If you have a 1 in 60*24 chance of guessing correctly then after 1000 guesses (potentially against different people) you have a 50 chance of being correct on one.

Could you explain your math here? Is there something you learn about the other digits when you make a wrong guess?

You could probably increase your odds significantly over time by analyzing the distribution of pins (and as others note, by making common sense observations you can also increase your odds)

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#127
post #79

And the hits just keep on coming... www.equifaxsecurity2017.com uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

The cert is signed by GeoTrust and works perfectly fine on my Chrome on Windows 10. [Edit: Ah, the chain is incomplete, see https://www.ssllabs.com/ssltest/analyze.html?d=www.equifaxse... ]

Here's an explaination of the error: https://serverfault.com/questions/788019/this-servers-certif...

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#128

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

I'm not a big fan of most tech certification efforts. They mainly document attendance at classes and/or ability to regurgitate trivia. They also tend to reward formality instead of quality, and slow progress. Consider, for example, if we'd had this sort of certification 10 years ago. It'd likely be filled with waterfall-style process requirements. Those don't actually increase safety; they just look impressive.

I'd be happier to see licensing and accountability. But it would have to have significant teeth. E.g., companies can't build systems of type X without somebody licensed. If there are problems with the system, then the person with the license faces personal fines and risk of suspension or loss of license. That would be less bad than certification, but it could still substantially slow industry progress if the licensing review board had a conservative tilt to it.

Of course, the real problem with most places is not engineers not knowing. It's with managers who push for things to happen despite what engineers advise. Licensing could sort of fix that, in that it could force engineers to act like professionals and refuse to do negligent work. But it still lets shitty managers off the hook.

So what I'd really like to see is a regulatory apparatus for PII. In the same way that the EPA comes after you for a toxics spill, an agency would come after you for a data spill. They investigate, they report, they impose massive fines when they think it's warranted. And when they do ream a company for negligent management of data, executives at all the peer companies get scared and listen to the engineers for a while.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#129
post #85
post #39

Earlier quoted context omitted.

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.

I think one of the problems is that it's just not societally necessary for 95% of software. If a game is shitty or an order entry system crashes occasionally, nobody dies. Nobody really even cares. Normal social and market mechanisms mean most software at least approaches adequacy.

In at least some of the areas where we really care about software quality (e.g., banking, medical devices) there are existing regulators who will fuck your shit up if you don't take certain aspects of quality seriously. Which is good, but I think it's part of why we don't have an industry-wide program.

Maybe we should take a lesson from Hammurabi:

"If a builder build a house for some one, and does not construct it properly, and the house which he built fall in and kill its owner, then that builder shall be put to death. If it kill the son of the owner the son of that builder shall be put to death." [1]

The occasional execution would probably make people much more serious about unit testing.

[1] http://mcadams.posc.mu.edu/txt/ah/Assyria/Hammurabi.html#Ham...

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#130
post #85
post #39

Earlier quoted context omitted.

"Critical systems" pretty vague, and could be used to describe any system that processes payments or other basic things we use. It's fundamentally different from malpractice in my opinion. In health care malpractice has obvious pieces of data - we know who the doctor is, we know their credentials, we know what information they had and when they had it, we know what they decided, what they prescribed, what they said.…

Real engineers have a system in place for this. It's called "Professional Engineer" and it's managed by NCEES. There is no possible reason that practice cannot directly apply to software engineering, except for the cultural refusal of software engineers to take responsibility for anything.

In fact, there has been a Software Engineering PE exam since 2013. It's not surprising that you don't hear a lot about it because most of the topics on the test would make the average CS student groan (requirements, maintenance, software development lifecycle, etc)

https://ncees.org/ncees-introduces-pe-exam-for-software-engi...

Exam specs: https://ncees.org/wp-content/uploads/2015/07/SWE-Apr-2013.pd...

Post reply on HN