The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.
You're oversimplifying. This has more to do with politics than SE technical competence. Banking software and systems are regulated end to end, because banking systems are literally the backbone of the global economy. Equifax? Not so much. This exposure hurts consumers, but it doesn't even put a dent in the economy as a whole. That is why these firms are allowed to operate with such shitty security. If they get hacked…
Equifax’s Maddening Unaccountability
21–30 of 238 posts
Re: Equifax’s Maddening Unaccountability
#22The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.
To be fair, it's not 'technical competency' but rather a broad range of operational, process, product and engineering competencies. Also, a lot of companies just don't have a thoughtful process for this. Think of how much data Google and FB have, and they've never been breached. As much as I loathe them, I actually feel more 'secure' with the data that is supposed to be secure with FB than with my local bank. FB depe…
HA HA HA HA HA HA lksahdgiua bregil nAG HA HA HA HAH!
http://www.reuters.com/article/net-us-facebook-security/face...
Re: Equifax’s Maddening Unaccountability
#23Now would be a great time to go long EFX in my opinion. The stock has been slammed while Equifax is being flogged in the court of public opinion, but I doubt this leak will have any lasting financial impact. Look at the result of the Target and Home Depot breaches: whether you like it or not, the companies are still technically the victims here and no court is going to bankrupt them for data breaches that are more an…
I thought about that too but it could also be possible that they may get bankrupted by lawsuits. I don't see Equifax as victim. I hope they will go down and be warning for the rest of the financial industry.
People seem to conflate the way they think things should be with the way things actually are.
Re: Equifax’s Maddening Unaccountability
#241. They realized that Equifax uses Struts. 2. They modified struts!
and 3. Equifax used the updated code on their servers.
DUUUUUHHHHHH!
Re: Equifax’s Maddening Unaccountability
#25The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.
To be fair, it's not 'technical competency' but rather a broad range of operational, process, product and engineering competencies. Also, a lot of companies just don't have a thoughtful process for this. Think of how much data Google and FB have, and they've never been breached. As much as I loathe them, I actually feel more 'secure' with the data that is supposed to be secure with FB than with my local bank. FB depe…
Re: Equifax’s Maddening Unaccountability
#26Earlier quoted context omitted.
>but I doubt this leak will have any lasting financial impact. I am going to have to stop you there. As someone who works in the financial sector, I have quite a different view of this situation. Best case scenario (for the organization) is that it is fined directly into bankruptcy and someone like FIS acquires them for pennies on the dollar. I am still waiting for CFPB to drop a nuclear bomb over this issue. There w…
Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.
Not really accurate because the exploit name, especially as generic as RCE, does not tell you how it was done. RCE can be a number of things that can be fixed in numerous ways. For example, file upload functionality with path manipulation and no file type validation may lead to RCE. This can certainly be removed with properly crafted file upload handling.
Some RCE, particularly on lower layers of the application stack, may be more difficult to defend against, especially in the case of unknown exploits.
Re: Equifax’s Maddening Unaccountability
#27The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.
You're oversimplifying. This has more to do with politics than SE technical competence. Banking software and systems are regulated end to end, because banking systems are literally the backbone of the global economy. Equifax? Not so much. This exposure hurts consumers, but it doesn't even put a dent in the economy as a whole. That is why these firms are allowed to operate with such shitty security. If they get hacked…
The already did, it's called the Gramm–Leach–Bliley Act:
> In terms of compliance, the key rules under the Act include The Financial Privacy Rule which governs the collection and disclosure of customers' personal financial information by financial institutions. It also applies to companies, regardless of whether they are financial institutions, who receive such information. The Safeguards Rule requires all financial institutions to design, implement and maintain safeguards to protect customer information. The Safeguards Rule applies not only to financial institutions that collect information from their own customers, but also to financial institutions – such as credit reporting agencies, appraisers, and mortgage brokers – that receive customer information from other financial institutions.
Note the inclusion of CRAs.
Re: Equifax’s Maddening Unaccountability
#28The problem is incompetence in our industry. Anyone who has worked long enough knows that technical competency is not rewarded (outside a few rare firms) in software engineering.
The problem is lack of commercial incentives. Apple, Google, Facebook, etc all have serious dollars at stake if they don't get security right. Equifax on the other hand...
Re: Equifax’s Maddening Unaccountability
#29Now would be a great time to go long EFX in my opinion. The stock has been slammed while Equifax is being flogged in the court of public opinion, but I doubt this leak will have any lasting financial impact. Look at the result of the Target and Home Depot breaches: whether you like it or not, the companies are still technically the victims here and no court is going to bankrupt them for data breaches that are more an…
>but I doubt this leak will have any lasting financial impact. I am going to have to stop you there. As someone who works in the financial sector, I have quite a different view of this situation. Best case scenario (for the organization) is that it is fined directly into bankruptcy and someone like FIS acquires them for pennies on the dollar. I am still waiting for CFPB to drop a nuclear bomb over this issue. There w…
There is zero chance of that happening. There's been no hint of this from any reputable source (i.e. not clickbait headlines). Will there be financial repercussions? Fines? Loss of stock value? Absolutely. Will Equifax go out of business or get sold? Absolutely not.
Re: Equifax’s Maddening Unaccountability
#30Earlier quoted context omitted.
Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.
"The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that." Not really accurate because the exploit name, especially as generic as RCE, does not tell you how it was done. RCE can be a number of things that can be fixed in numerous ways. For example, file upload functionality with path manipulation and no file type validation may lead to RCE. This can certainly be removed w…