Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

21–30 of 238 posts

Re: Equifax’s Maddening Unaccountability

#21
post #13

The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.

You're oversimplifying. This has more to do with politics than SE technical competence. Banking software and systems are regulated end to end, because banking systems are literally the backbone of the global economy. Equifax? Not so much. This exposure hurts consumers, but it doesn't even put a dent in the economy as a whole. That is why these firms are allowed to operate with such shitty security. If they get hacked…

[deleted]

Re: Equifax’s Maddening Unaccountability

#22

The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.

To be fair, it's not 'technical competency' but rather a broad range of operational, process, product and engineering competencies. Also, a lot of companies just don't have a thoughtful process for this. Think of how much data Google and FB have, and they've never been breached. As much as I loathe them, I actually feel more 'secure' with the data that is supposed to be secure with FB than with my local bank. FB depe…

>they've never been breached

HA HA HA HA HA HA lksahdgiua bregil nAG HA HA HA HAH!

http://www.reuters.com/article/net-us-facebook-security/face...

Re: Equifax’s Maddening Unaccountability

#23
post #12

Now would be a great time to go long EFX in my opinion. The stock has been slammed while Equifax is being flogged in the court of public opinion, but I doubt this leak will have any lasting financial impact. Look at the result of the Target and Home Depot breaches: whether you like it or not, the companies are still technically the victims here and no court is going to bankrupt them for data breaches that are more an…

I thought about that too but it could also be possible that they may get bankrupted by lawsuits. I don't see Equifax as victim. I hope they will go down and be warning for the rest of the financial industry.

Target lost tens of millions of credit card numbers and paid just over $18 million to settle every lawsuit against them.

People seem to conflate the way they think things should be with the way things actually are.

Re: Equifax’s Maddening Unaccountability

#25

The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.

To be fair, it's not 'technical competency' but rather a broad range of operational, process, product and engineering competencies. Also, a lot of companies just don't have a thoughtful process for this. Think of how much data Google and FB have, and they've never been breached. As much as I loathe them, I actually feel more 'secure' with the data that is supposed to be secure with FB than with my local bank. FB depe…

HAHAHAHAHAHAHHA

https://www.theguardian.com/technology/2017/jun/16/facebook-...

Re: Equifax’s Maddening Unaccountability

#26
post #11

Earlier quoted context omitted.

>but I doubt this leak will have any lasting financial impact. I am going to have to stop you there. As someone who works in the financial sector, I have quite a different view of this situation. Best case scenario (for the organization) is that it is fined directly into bankruptcy and someone like FIS acquires them for pennies on the dollar. I am still waiting for CFPB to drop a nuclear bomb over this issue. There w…

Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.

"The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that."

Not really accurate because the exploit name, especially as generic as RCE, does not tell you how it was done. RCE can be a number of things that can be fixed in numerous ways. For example, file upload functionality with path manipulation and no file type validation may lead to RCE. This can certainly be removed with properly crafted file upload handling.

Some RCE, particularly on lower layers of the application stack, may be more difficult to defend against, especially in the case of unknown exploits.

Re: Equifax’s Maddening Unaccountability

#27
post #13

The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.

You're oversimplifying. This has more to do with politics than SE technical competence. Banking software and systems are regulated end to end, because banking systems are literally the backbone of the global economy. Equifax? Not so much. This exposure hurts consumers, but it doesn't even put a dent in the economy as a whole. That is why these firms are allowed to operate with such shitty security. If they get hacked…

> What is the incentive for congress to enact laws regulating corporate handling of consumer data?

The already did, it's called the Gramm–Leach–Bliley Act:

> In terms of compliance, the key rules under the Act include The Financial Privacy Rule which governs the collection and disclosure of customers' personal financial information by financial institutions. It also applies to companies, regardless of whether they are financial institutions, who receive such information. The Safeguards Rule requires all financial institutions to design, implement and maintain safeguards to protect customer information. The Safeguards Rule applies not only to financial institutions that collect information from their own customers, but also to financial institutions – such as credit reporting agencies, appraisers, and mortgage brokers – that receive customer information from other financial institutions.

Note the inclusion of CRAs.

Re: Equifax’s Maddening Unaccountability

#28
post #20

The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.

The problem is lack of commercial incentives. Apple, Google, Facebook, etc all have serious dollars at stake if they don't get security right. Equifax on the other hand...

Since when is 3 billion dollars in revenue not serious money?

Re: Equifax’s Maddening Unaccountability

#29
post #11

Now would be a great time to go long EFX in my opinion. The stock has been slammed while Equifax is being flogged in the court of public opinion, but I doubt this leak will have any lasting financial impact. Look at the result of the Target and Home Depot breaches: whether you like it or not, the companies are still technically the victims here and no court is going to bankrupt them for data breaches that are more an…

>but I doubt this leak will have any lasting financial impact. I am going to have to stop you there. As someone who works in the financial sector, I have quite a different view of this situation. Best case scenario (for the organization) is that it is fined directly into bankruptcy and someone like FIS acquires them for pennies on the dollar. I am still waiting for CFPB to drop a nuclear bomb over this issue. There w…

> Best case scenario (for the organization) is that it is fined directly into bankruptcy and someone like FIS acquires them for pennies on the dollar. I am still waiting for CFPB to drop a nuclear bomb over this issue.

There is zero chance of that happening. There's been no hint of this from any reputable source (i.e. not clickbait headlines). Will there be financial repercussions? Fines? Loss of stock value? Absolutely. Will Equifax go out of business or get sold? Absolutely not.

Re: Equifax’s Maddening Unaccountability

#30

Earlier quoted context omitted.

Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.

"The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that." Not really accurate because the exploit name, especially as generic as RCE, does not tell you how it was done. RCE can be a number of things that can be fixed in numerous ways. For example, file upload functionality with path manipulation and no file type validation may lead to RCE. This can certainly be removed w…

Fair enough. I more meant that after an attacker has achieved RCE, no amount of encryption or other practices can protect sensitive info in your database.
Post reply on HN