Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

51–60 of 238 posts

Re: Equifax’s Maddening Unaccountability

#51

I just read about how the hack was done. Shockingly stupidly easy! 1. They realized that Equifax uses Struts. 2. They modified struts! and 3. Equifax used the updated code on their servers. DUUUUUHHHHHH!

Do you have a source for 2? I'd like to read more about it.

Re: Equifax’s Maddening Unaccountability

#52

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

We have all agreed. We gave permission to any company that extends credit. They give our information to these credit reporting agencies on an on-going basis, personal information, including what our payment behavior and history is.

All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very similar to Google, et al. We aren't the consumer. They collect our personal information, vastly more than credit agencies. And the real customer are the advertisers who pay Google. The difference is, we probably trust Google more than Equifax (even before all of this).

A month ago, my mom said she wanted to start using Uber on her phone. I explained how to install it, and when she did (as well as the Lyft app for that matter) it wanted access to her camera, photos, contacts, a list of information on her phone. And she said fuck no. And refused to give permission. So she still uses cabs and pays cash.

Re: Equifax’s Maddening Unaccountability

#53
post #34

Earlier quoted context omitted.

Expecting perfection is wrong. There's 120 millions of lines of code in an A380, and planes don't crash due to software bugs. Why is it wrong to expect perfection in critical infrastructure? Something went wrong somewhere in software engineering. My HP42s calculator has about 6 insignificant bugs that you need to get out of your way to trigger. Your new cellphone on the other hand, when you turn it on it downloads a…

You're comparing a relatively cheap credit report to a $400 million dollar airplane with a 15-25 billion euro program cost. Not to mention aerospace has a 100 years of innovation and has actual lives at stake. The internet, what 30ish years? Not to mention network security is a relatively new concern.

At the end of the day it's a liability issue. If a plane crashes due to a software issue there's going to be civil suits to recover damages, very possible they'll also sue for criminal negligence.

Why is software immune? You ask yourself about cost of the Office of Personnel Management hack from two years ago, and before that it was the biometrics database from the USCIS.

Re: Equifax’s Maddening Unaccountability

#54
post #18

Earlier quoted context omitted.

Thats exactly what I'm saying. There is near zero incentive for congress to enact consumer protection legislation.

There's incentive (as it's their job, or is said to be). What there isn't is a downside if they don't.

If we're talking about economic incentive, having no downside for not doing thing A is equivalent to having no incentive to do thing A. Re: opportunity cost.

Re: Equifax’s Maddening Unaccountability

#55

Earlier quoted context omitted.

Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.

Having root on a web server shouldn't give you access to 147 million customer records.

I'm eagerly awaiting the technical details of the attack. If it turns out that their web server has 100% unfettered access to the database then I'll gladly pick up a pitchfork as well.

I'm wondering if Equifax is using Struts-provided REST for its entire architecture. If that's the case, gaining access to the web server was only the first step. From there the attacker could perform RCE on sensitive services.

Re: Equifax’s Maddening Unaccountability

#56
post #18
post #15

Earlier quoted context omitted.

I'm not sure they actually care in Washington. I was impacted by the OPM breech. I got a form letter and some credit monitoring. All that outrage and, as near as I can tell, not a damned thing has changed. I might be biased and jaded.

Thats exactly what I'm saying. There is near zero incentive for congress to enact consumer protection legislation.

I was adding to, not arguing with.

Re: Equifax’s Maddening Unaccountability

#57

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

Common misconception. They actually do need your approval, it's just that that approval is buried in the mountains of legalese you sign whenever you sign up for a bank account, credit card or loan.

Although, in the case of identity fraud, they don't have your approval. Someone else signed the paperwork.

Re: Equifax’s Maddening Unaccountability

#58
post #52

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

We have all agreed. We gave permission to any company that extends credit. They give our information to these credit reporting agencies on an on-going basis, personal information, including what our payment behavior and history is. All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very sim…

Since when does Uber ask for use of your camera or access to photos? And for what?

Re: Equifax’s Maddening Unaccountability

#59
post #34

Earlier quoted context omitted.

Expecting perfection is wrong. There's 120 millions of lines of code in an A380, and planes don't crash due to software bugs. Why is it wrong to expect perfection in critical infrastructure? Something went wrong somewhere in software engineering. My HP42s calculator has about 6 insignificant bugs that you need to get out of your way to trigger. Your new cellphone on the other hand, when you turn it on it downloads a…

You're comparing a relatively cheap credit report to a $400 million dollar airplane with a 15-25 billion euro program cost. Not to mention aerospace has a 100 years of innovation and has actual lives at stake. The internet, what 30ish years? Not to mention network security is a relatively new concern.

With a market cap of $18 billion for Equifax, it seems like they had the resources to get this right. I see the difference as who shoulders the cost. If you pay $400 million for a defective plane, you have one company whose toes you will hold to the fire. If you lose data worth $400 million for 138 million people, you have about $2.89 average per compromised person, so no single person will really go that far out of their way to crucify you, and if one does, they have perhaps tens of thousands of dollars to use in the legal system holding you accountable, not the millions one large wronged party may spend on it. In aggregate economic terms, in actual loss and negligence, I don't see that much difference. If you want to steal a lot, steal a small amount from a large number of people. It looks to me more like a matter of the feasibility of getting away with it.

Re: Equifax’s Maddening Unaccountability

#60

Earlier quoted context omitted.

Having root on a web server shouldn't give you access to 147 million customer records.

I'm eagerly awaiting the technical details of the attack. If it turns out that their web server has 100% unfettered access to the database then I'll gladly pick up a pitchfork as well. I'm wondering if Equifax is using Struts-provided REST for its entire architecture. If that's the case, gaining access to the web server was only the first step. From there the attacker could perform RCE on sensitive services.

If it turns out that their web server has 100% unfettered access to the database then I'll gladly pick up a pitchfork as well.

You may want to think twice. Try to design an architecture that doesn't have that. If you think it through, you'll realize the best you can do is not to deny access, but to monitor access so that any statistical deviation in requests-per-hour will trigger an alarm. Yet nobody does that, so why should Equifax have been a pioneer in this method?

This is the uncomfortable truth that everyone is obscuring here. There wasn't a solution. Equifax got owned, and they happened to have a trove of data. Everyone now wants to see their heads roll, but you too would find yourself in the same situation if you have an RCE on your servers.

Post reply on HN