Live data from Hacker News

Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

bloomberg.com

31–40 of 80 posts

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#31
I do performance / app triage work, but see the same thing. Often I walk in to a supposed "emergency" only to discover the problem has been occurring for months, if not years. Often, there is a significant cost (IE: in the millions) but either the organization isn't willing to remediate, or isn't even aware of the full scope of the cost (IE: "It's not my budget so I don't care"). In at least one case, I came across a security problem where the response was "oh yeah, we've known about that for years". Sigh. Sadly, too often unless companies have a very large customer who gets angry with them, or they are publicly shamed for a problem, they just let it magically go.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#32
post #21

If they had an outside security firm helping them starting in March, and another breach in July, that doesn't say much for the capabilities and competency of the security firm.

Not 'helping them', just diagnosing a breach. Part of their due diligence to make sure they don't run afoul of the reporting laws. Once it was determined they didn't have proof of data leaving the network, I imagine they booted that security company immediately. They're not going to spend money to improve their security just because a non-reportable breach occurred. They don't give a shit about your data.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#33

I'm sure this looks good for the insider trading news.

> Pros for not prosecuting: The size of the sells were truly negligible for all executives involved, in proportion to how many shares they have and routinely liquidate. The same argument that there were any sells at all would been made regardless of the number of shares. A company that size will always have material non public information. Equifax's OPSEC was horrible all along and a gigantic leak was bound to happen…

If I were a shareholder in Equifax, I would probably be looking very closely at what those executives are paid. They adamantly insist that they had no idea about the most significant thing to happen at their company in years. Clearly, they're not just lazy, they have to be aggressively, emphatically incompetent.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#34
post #10
post #7

I think it's good news- if your identity has not been used, there's less chance that it will be, because the data has been already out for that long.

I was told they usually aren't used until at least a year after the fact, because this line of reasoning. Not sure how true that is.

Perhaps not true THIS time at least...

https://krebsonsecurity.com/2017/09/equifax-hackers-stole-20...

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#35
post #22

Earlier quoted context omitted.

It's quite possible the security firm was asked to audit their systems, but not asked (or paid) to fix them.

A lot of people want you to come in and find a quick answer and fix, rarely allowing a full proper investigation. Many times they're adverse to spending money and want to cut corners where they can. It's actually disheartening. Much like one of the posters above, I've seen people purposely stop investigations because if the investigation reported on known issues it would open up more questions about other wrong doing…

So you can't do this with accounting audit, so laws should be updated to make security audits the same!

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#36
post #28
post #21

If they had an outside security firm helping them starting in March, and another breach in July, that doesn't say much for the capabilities and competency of the security firm.

I am not sure about origins, but the name they disclosed in their PR is of a very capable outfit.

If that's the case, we must assume then that any recommendations they made were summarily ignored, given the subsequent breach in July?

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#37

I do performance / app triage work, but see the same thing. Often I walk in to a supposed "emergency" only to discover the problem has been occurring for months, if not years. Often, there is a significant cost (IE: in the millions) but either the organization isn't willing to remediate, or isn't even aware of the full scope of the cost (IE: "It's not my budget so I don't care"). In at least one case, I came across a…

I came across a "hole" in the design of a vendor I was evaluating. Their fancy Java UI actually just downloaded plaintext root credentials to their MySQL database. All security was client side. As a bonus the root credentials were debug logged to the user's local computer.

Making it worse, they actively sold this as a multi-tenant platform to be used with mutually untrusting parties.

When I met with engineering and started to explain, they started smiling and said "this is a known issue and we're going to fix it in our next version."

Quite some time later I ran across people using it in the wild and they had not passed a lot of the glaring holes. Even their newer version had a hidden input field on the edit profile page named "IsAdmin". This did exactly what you think.

They ended up having a successful exit as far as I know and I've never heard anyone speak ill of them security-wise.

Telecom is a mess. These holes are easily exploitable for direct profit. But there's so much more low-hanging fruit, I don't think people bother.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#38
post #19

> One possible explanation, according to several veteran security experts consulted by Bloomberg, is that the investigation didn’t uncover evidence that data was accessed. Most data breach disclosure laws kick in only once there’s evidence that sensitive personal identifying information like social security numbers and birth dates have been taken. There was one company (very well known) I know of that was breached, b…

Sure, that combined with the fact that courts simply refuse to refer to anything involving software a 'negligence', no matter how extravagantly negligent it might be, would make that a pretty good strategy. The only flaw in it, really, is that it would also open you up to things like the Sony hack which actually had them shut down operations for awhile. As much as companies REALLY do not want to ever admit it, no mat…

Maybe this is the unintended benefit of companies like domino's claiming they're a "tech business that sells pizza". I'd love to see that language used in an agument that the company has made tech it's core competency and that lowers the bar for negligence.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#39
post #35

Earlier quoted context omitted.

A lot of people want you to come in and find a quick answer and fix, rarely allowing a full proper investigation. Many times they're adverse to spending money and want to cut corners where they can. It's actually disheartening. Much like one of the posters above, I've seen people purposely stop investigations because if the investigation reported on known issues it would open up more questions about other wrong doing…

So you can't do this with accounting audit, so laws should be updated to make security audits the same!

I suppose the difference is that in accounting, any irregularities or shennanigans are quantifiable in dollars. Security breaches maybe sometimes are, but often are not. I'm guessing there nobody able to prove that his or her identity was stolen as a result of this breach, to say nothing of being able to specify a dollar amount of loss that can be backed up.

With often vague or only theoretical damages, it's harder to muster support for draconian consequences.

Also people can sort of understand accounting. Dollars and cents and balances are something most people can comprehend. Computer software and security breaches, on the other hand, are much more of a black box for most people. They can't intuitively understand what's sensisible and reasonable and what would constitute negligence when it comes to protecting software sytems and data, other than by relying on what other people tell them.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#40

I do performance / app triage work, but see the same thing. Often I walk in to a supposed "emergency" only to discover the problem has been occurring for months, if not years. Often, there is a significant cost (IE: in the millions) but either the organization isn't willing to remediate, or isn't even aware of the full scope of the cost (IE: "It's not my budget so I don't care"). In at least one case, I came across a…

Risk v. reward I'm afraid. The Sarbanes-Oxley legislation attempted to put skin in the game for the C execs in public companies; so, I cannot help but notice how many public companies delisted, went private after that. The whole of the corporate charter was meant to insulate investors' personal wealth against risks. I guess this is where licensing can provide a backstop to poor development practices, but it seems to have not really caught on.
Post reply on HN