Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
31–40 of 80 posts
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#32If they had an outside security firm helping them starting in March, and another breach in July, that doesn't say much for the capabilities and competency of the security firm.
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#33I'm sure this looks good for the insider trading news.
> Pros for not prosecuting: The size of the sells were truly negligible for all executives involved, in proportion to how many shares they have and routinely liquidate. The same argument that there were any sells at all would been made regardless of the number of shares. A company that size will always have material non public information. Equifax's OPSEC was horrible all along and a gigantic leak was bound to happen…
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#34I think it's good news- if your identity has not been used, there's less chance that it will be, because the data has been already out for that long.
I was told they usually aren't used until at least a year after the fact, because this line of reasoning. Not sure how true that is.
https://krebsonsecurity.com/2017/09/equifax-hackers-stole-20...
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#35Earlier quoted context omitted.
It's quite possible the security firm was asked to audit their systems, but not asked (or paid) to fix them.
A lot of people want you to come in and find a quick answer and fix, rarely allowing a full proper investigation. Many times they're adverse to spending money and want to cut corners where they can. It's actually disheartening. Much like one of the posters above, I've seen people purposely stop investigations because if the investigation reported on known issues it would open up more questions about other wrong doing…
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#36If they had an outside security firm helping them starting in March, and another breach in July, that doesn't say much for the capabilities and competency of the security firm.
I am not sure about origins, but the name they disclosed in their PR is of a very capable outfit.
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#37I do performance / app triage work, but see the same thing. Often I walk in to a supposed "emergency" only to discover the problem has been occurring for months, if not years. Often, there is a significant cost (IE: in the millions) but either the organization isn't willing to remediate, or isn't even aware of the full scope of the cost (IE: "It's not my budget so I don't care"). In at least one case, I came across a…
Making it worse, they actively sold this as a multi-tenant platform to be used with mutually untrusting parties.
When I met with engineering and started to explain, they started smiling and said "this is a known issue and we're going to fix it in our next version."
Quite some time later I ran across people using it in the wild and they had not passed a lot of the glaring holes. Even their newer version had a hidden input field on the edit profile page named "IsAdmin". This did exactly what you think.
They ended up having a successful exit as far as I know and I've never heard anyone speak ill of them security-wise.
Telecom is a mess. These holes are easily exploitable for direct profit. But there's so much more low-hanging fruit, I don't think people bother.
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#38> One possible explanation, according to several veteran security experts consulted by Bloomberg, is that the investigation didn’t uncover evidence that data was accessed. Most data breach disclosure laws kick in only once there’s evidence that sensitive personal identifying information like social security numbers and birth dates have been taken. There was one company (very well known) I know of that was breached, b…
Sure, that combined with the fact that courts simply refuse to refer to anything involving software a 'negligence', no matter how extravagantly negligent it might be, would make that a pretty good strategy. The only flaw in it, really, is that it would also open you up to things like the Sony hack which actually had them shut down operations for awhile. As much as companies REALLY do not want to ever admit it, no mat…
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#39Earlier quoted context omitted.
A lot of people want you to come in and find a quick answer and fix, rarely allowing a full proper investigation. Many times they're adverse to spending money and want to cut corners where they can. It's actually disheartening. Much like one of the posters above, I've seen people purposely stop investigations because if the investigation reported on known issues it would open up more questions about other wrong doing…
So you can't do this with accounting audit, so laws should be updated to make security audits the same!
With often vague or only theoretical damages, it's harder to muster support for draconian consequences.
Also people can sort of understand accounting. Dollars and cents and balances are something most people can comprehend. Computer software and security breaches, on the other hand, are much more of a black box for most people. They can't intuitively understand what's sensisible and reasonable and what would constitute negligence when it comes to protecting software sytems and data, other than by relying on what other people tell them.
Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
#40I do performance / app triage work, but see the same thing. Often I walk in to a supposed "emergency" only to discover the problem has been occurring for months, if not years. Often, there is a significant cost (IE: in the millions) but either the organization isn't willing to remediate, or isn't even aware of the full scope of the cost (IE: "It's not my budget so I don't care"). In at least one case, I came across a…