Live data from Hacker News

Equifax security freeze PINs are the timestamp of when you request the freeze

twitter.com

171–180 of 193 posts

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#171

It's time to have a mandatory certification for people who develop critical systems. After such certification, you can consider such an implementation a malpractice, and sue them for it (of course the penalty is paid by the insurance company which sold the malpractice insurance). Doctors, lawyers, and many other professions have such system, why can't we have it as well?

Various tech industries do have it.

https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#172

This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…

> _involuntarily_

This is probably part of the explanation.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#173

Earlier quoted context omitted.

It's rigorous, but in all the wrong ways. At $DAY_JOB our security falls into two buckets (1) PCI and (2) stuff that keeps us secure. IDK if it's possible to have a widely accepted security standard that isn't checking nonsensical and out-of-date boxes.

Well, it could be worse: 1) Stuff that keeps you insecure (a.k.a ISO 27001 ISMS stuff) 2) Stuff that somewhat helps, but is covered by fluff (a.k.a. PCI-DSS) 3) Stuff that actually keeps you secure. PCI-DSS at least gives you a sledgehammer to convince lazy low-level managers to dump ciphers like RC4 and encrypt some of their data. It's not utopia, and it does err on the side of perpetuating banks' infatuation with 3…

PCI is why we have weak passwords that we have to reinvent every 90 days.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#174
post #68

Earlier quoted context omitted.

As licensed professionals, they work under the knowledge that there are practices and outcomes that can cause them to lose their licenses.

Once again, may be it is time for such a thing to exist for software engineers who aren't web devs.

It's been suggested, but AFAIK some find fundamental aspects of software development to make it hard if not impossible for it to ever be True Engineering. I'm pulling this out of my back pocket on a Saturday evening, so Google for more, but there are arguments on both sides that go back some years. Heck, google "is software development engineering" and you'll find long Quora threads on the topic.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#176
post #88

True thing: until recently you could remove hard inquiries from your credit report merely by pulling your own credit so often in one month using an array of daily monitoring services that you would overflow the field and bump off legit inquiries. I did this in 2009-10, it had been going on for a while, and lasted for a while but sadly I hear they've solved it seemingly by nightly batch job to remove your own credit p…

How many requests, specifically, did you have to have to overflow the field?

75-100 in a month iirc

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#177

And the hits just keep on coming... www.equifaxsecurity2017.com uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported. Error code: SEC_ERROR_UNKNOWN_ISSUER

You literally cannot make this up! The CSO is a graduate in music ffs! The website notifying customers about a security incident has an invalid certificate. The mind boggles how such companies are running day-to-day.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#178
post #95

This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform. Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other…

You're surprised that large companies are incompetent? My experience has been that the main product of most companies is management politics. Actually shipping product is nearly irrelevant to everyone's daily activities. In some cases, people get punished for being competent. One company I worked with made it clear they had no interest in listening to competent people. People were promoted for their ability to suck u…

I worked here

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#179
post #153

Earlier quoted context omitted.

In general it would not be, now that the personal data of 100+ millions of people have been stolen from these clowns, it seems relevant. Leadership sets the priorities, and expectations. They get paid disproportionately more than other employees and I think they should be scrutinized and bear responsibility correspondingly. But I have no doubt they probably found someone lower in the ranks as a scapegoat. "Joe was in…

I'm not saying we shouldn't have serious questions about his competence after this breach. Rather, my point is that we should be questioning his competence (and that of the rest of the executive team's) due to this breach, not his credentials. If he had a CS degree, that wouldn't make him any less responsible for this massive data leak.

Usually, the larger the company, the deeper processes go, shielding it from individual incompetence (so the company can hire for easy to measure attributes, like compensation, and protect itself from difficult metrics, like technical competence). Unfortunately, processes also prevent individual competence to have a noticeable impact on the company.

If I got the story right, this bug was present for the last 9 years and patched upstream a couple days before the leak. Some measures could have prevented its exploitation or reduced its impact, like throttling by IP, one-time session keys and so on - and should be in place for any serious application - but it's entirely possible they had fixed schedule for patches and mis-evaluated this flaw as non-critical.

A LOT of companies carry obsolete dependencies for a long time.

Re: Equifax security freeze PINs are the timestamp of when you request the freeze

#180
post #29

Earlier quoted context omitted.

Developers don't control budgets and deadlines at large companies, management does. So what does this "certified" individual do when he's given a project without resources allocated for proper security auditing? Does he intentionally get fired for refusing the assignment? That works if he has bountiful savings, no mortgage, no kids. Surely no unethical contracting company will pick up the job after he leaves...

If only there were more software jobs out there, then they wouldn't be hemmed in so intractably.

Finding another software job is insufficient. You need to find one that gives its employees the time and space they say need regardless of other competitive or financial pressures. Not so easy.
Post reply on HN