Earlier quoted context omitted.
> The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that. If the vulnerability used turns out to be the Struts one that was announced at the beginning of the year, then the "magic" here would have been quite muggle-like: update the damn dependency. Not doing so is negligence, plain and simple. (I agree with you, though, that EFX will almost certainly come out of this rel…
The statement released by Apache said that, if the attack did use the REST plugin vulnerability in Struts, then it would have been a zero-day at the time of use.
Equifax’s Maddening Unaccountability
201–210 of 238 posts
Re: Equifax’s Maddening Unaccountability
#202Americans woke up to news of yet another mass breach of their personal data. Americans woke up to news of yet another mass breach of data about them. FTFY
could you elaborate on what you mean by making this distinction, please?
Re: Equifax’s Maddening Unaccountability
#203Earlier quoted context omitted.
I'm sorry. I really think we're talking past each other. At this point I'm having a really hard time figuring out what you're trying to say. I see you equating Struts and software practices with the businesses that use software. I see those as two separate things. > Nobody MADE Equifax use Struts. Yup. > The source is open to inspection. Yup. > Let's see how many audits Equifax did on the source code with no warranty…
>I place the responsibly Nobody cares where you, or I, place it. You don't write for the NYTimes. You don't have that sort of sphere of influence. >with the company using Struts in their product, not the Struts dev. They don't. http://nypost.com/2017/09/08/equifax-blames-giant-breach-on-... It's very easy to explain to the public. "Those software hacker people did this to you. Look, here he is. He made the faulty sof…
The author was not blaming the Struts guy. She was blaming Equifax, 100%. She would blame the decision to use Struts and assume the unavoidable risk associated with such a decision, not the development of Struts itself.
Literally every single point made in the article is about Equifax dodging accountability for their choices, and Struts is never mentioned. What on Earth makes you assert with such total certainty that she's blaming the Struts developer?
Re: Equifax’s Maddening Unaccountability
#204Re: Equifax’s Maddening Unaccountability
#205Re: Equifax’s Maddening Unaccountability
#206Re: Equifax’s Maddening Unaccountability
#207Earlier quoted context omitted.
I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…
Well here in europe it didn't happen all at once. It was a gradual rolling of chip based cards, atms and terminals. There was a non-insignificant amount of time where some atms / pos terminals would reject your card because you/it didn't have the right technology. But ultimately I think its the people themselves that demand more security from their banks. E.g. Bank one introduces chip based cards and more people choo…
Here in the U.S. the next step is usually asking for the social security number. I called VISA/Citi to re-activate my card after traveling and they asked for the associated phone number with my account. Neither of these are especially secure, in my opinion.
Re: Equifax’s Maddening Unaccountability
#208Earlier quoted context omitted.
Having root on a web server shouldn't give you access to 147 million customer records.
I'm eagerly awaiting the technical details of the attack. If it turns out that their web server has 100% unfettered access to the database then I'll gladly pick up a pitchfork as well. I'm wondering if Equifax is using Struts-provided REST for its entire architecture. If that's the case, gaining access to the web server was only the first step. From there the attacker could perform RCE on sensitive services.
For one.
Re: Equifax’s Maddening Unaccountability
#209Earlier quoted context omitted.
I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…
Re: Cost of fraud. Agreed. It still amazes me how prevalent credit card fraud is. Certainly that's preventable - if they want it to be. The problem is, the banks don't bear that cost, the consumer does. Even if the bank factors the loss into the cost of doing business, that still gets passed on to the consumer.
It is merchants (stores, internet sites) that bear the cost of fraud.
Re: Equifax’s Maddening Unaccountability
#210With that I also saw that cyber security is and will be the biggest threats of the next decade. They are many cyber security companies these days but I didn't see a single company moving forward to support the Equifax team to figure out what happened and how it can be prevented. Cyber security companies should have volunteered for the cause.