Live data from Hacker News

Equifax takes down web page after reports of new hack

reuters.com

51–60 of 143 posts

Re: Equifax takes down web page after reports of new hack

#51
post #8

Earlier quoted context omitted.

It seems abundantly clear that Equifax's incompetence is _systemic_. Under the presumption that they could have hired better engineers, I fully believe they would have managed them into submission.

I'd be amazed if the average/combined skill level of engineers at any large company exceeds the average/combined skill level of the people trying to compromise its security. And that's not taking into account the bureaucratic overhead necessary to make changes in such an environment. There are very good, and very bad, reasons why upgrading insecure software and fixing other security holes takes too much time and effo…

Libraries, frameworks, and other security systems don't have to be developed in-house. It's just like basic data structures and algorithms: few ought to be rolling their own and should instead be using libraries.

Re: Equifax takes down web page after reports of new hack

#52
post #39

Earlier quoted context omitted.

Doesn't this require you to trust Equifax to enforce and honor the freeze? I think the solution is "I don't want my report or any of my data in any sort of control or possession of Equifax". Where is that solution?

What is "your data" exactly? And in the limit, how far does this go? Here's a question: who owns your drivers license? Here's a hint: it isn't you. Can you "own" you mailing address? Copyright and trademark it, make everyone ask permission from you before they write it down? What about your salary? Should your employer have to ask every time they use your salary number in some way, say in aggregate statistics or repo…

As far as copyright, small snippets of information or sentence fragments are not copyrightable, but collections of data are.

>Society might grind to a halt, we would be inundated with virtual and physical pop-ups asking "your landlord wants access to your phone number to place a call to you, will you allow it?"

That is how messaging works on many newer systems like Facebook or Instagram, and people appear to find that level of control desirable, not annoying. The only reason the phone system works with public numeric IDs that anyone can dial is that whole thing is a relic from 50 years ago.

Re: Equifax takes down web page after reports of new hack

#53

it's amazing how much the finance industry can get away with. like honest-to-goodness amazing. it's really impressive how these people can have such a death-grip on society. honestly, i'm more curious than mad. how is such a thing even possible? i mean, wow.

Well, these guys are simply too big to fail. Equifax cannot go bust, otherwise loads of consumer credit (mortgages, car loans etc) would freeze up, causing huge harm to the economy. The market likely knows this, hence the stable stock price.

Equifax cannot go bust, otherwise loads of consumer credit (mortgages, car loans etc) would freeze up

Nope - there are two others who will gladly take up the slack.

Re: Equifax takes down web page after reports of new hack

#54
post #39

Earlier quoted context omitted.

Doesn't this require you to trust Equifax to enforce and honor the freeze? I think the solution is "I don't want my report or any of my data in any sort of control or possession of Equifax". Where is that solution?

What is "your data" exactly? And in the limit, how far does this go? Here's a question: who owns your drivers license? Here's a hint: it isn't you. Can you "own" you mailing address? Copyright and trademark it, make everyone ask permission from you before they write it down? What about your salary? Should your employer have to ask every time they use your salary number in some way, say in aggregate statistics or repo…

The issue is that I am responsible for people using this data, but don’t own it like you mentioned. If the banks were responsible for giving out fraudulent loans and there was an easier way to prove that they were fradualent without this PI, then I wouldn’t care. But I have to care right now.

Re: Equifax takes down web page after reports of new hack

#55
post #51

Earlier quoted context omitted.

I'd be amazed if the average/combined skill level of engineers at any large company exceeds the average/combined skill level of the people trying to compromise its security. And that's not taking into account the bureaucratic overhead necessary to make changes in such an environment. There are very good, and very bad, reasons why upgrading insecure software and fixing other security holes takes too much time and effo…

Libraries, frameworks, and other security systems don't have to be developed in-house. It's just like basic data structures and algorithms: few ought to be rolling their own and should instead be using libraries.

Yes and no; it was Apache code that was exploited. The failure tho' wasn't technical really; it was the lack of urgency in patching once the flaw was known, which is 100% on management

Re: Equifax takes down web page after reports of new hack

#56

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

For this new issue, the problem is that by the time you're even halfway through the sentence "part of Equifax’s website was under the control of attackers trying to trick visitors into installing fraudulent Adobe Flash updates that could infect computers with malware", 90% of people I have decided that it's over their head and stopped listening.

Re: Equifax takes down web page after reports of new hack

#57

I feel like this has to do with Equifax basically not being punished in any major way over the last breach. Their stocks are still priced reasonably well, most of their board is still intact, and US citizens are still required to work with them for credit reasons. And the worst part is, I have no idea how I as a person could say "I don't want to do work with Equifax because I don't trust them." And if anybody has sug…

This has nothing to do with punishment. This is the result of a broken system. Most fortune 500 companies pay the ransomware price and the public is never aware of any breach. The idea of storing information on a connected network is the problem. We need to return to the brick and mortar way of storing data, i.e. Tightly guarded central facilities. Nobody should be able to steal 148 million accounts with the click of a button.

Re: Equifax takes down web page after reports of new hack

#58
post #8
post #6

The incompetence is mindblowing. Could this be a good argument for software engineers to get their professional license?

It seems abundantly clear that Equifax's incompetence is _systemic_. Under the presumption that they could have hired better engineers, I fully believe they would have managed them into submission.

This particular site looks like it might not have been touched for a decade or more.

So there is also the argument of "any engineers at all" vs "better engineers".

Re: Equifax takes down web page after reports of new hack

#59
post #38
post #31

Yes, this was discussed earlier today: https://news.ycombinator.com/item?id=15456221 And debunked...it wasn't a hack of the Equifax web site, but a malware package delivered by 3rd party analytics company, Fireclick.

Not exactly. Equifax has hardcoded references to an akamai cache of a domain (hints.netflame.cc) in their own pages[1]. That domain was owned by Fireclick (né Digital River) at one time, but changed ownership on November 15, 2016. The current owner is a Thai national using a personal Gmail address as the registration info. Equifax should be responsible for what 3rd party domains it is referencing in their pages. [1]…

[deleted]

Re: Equifax takes down web page after reports of new hack

#60
post #39

Earlier quoted context omitted.

Doesn't this require you to trust Equifax to enforce and honor the freeze? I think the solution is "I don't want my report or any of my data in any sort of control or possession of Equifax". Where is that solution?

What is "your data" exactly? And in the limit, how far does this go? Here's a question: who owns your drivers license? Here's a hint: it isn't you. Can you "own" you mailing address? Copyright and trademark it, make everyone ask permission from you before they write it down? What about your salary? Should your employer have to ask every time they use your salary number in some way, say in aggregate statistics or repo…

>virtual and physical pop-ups asking "your landlord wants access to your phone number to place a call to you, will you allow it?"

I would grant the landlord access to contact me while I still have a business relationship with her.

This dire scenario you are trying to paint frankly doesn't sound that bad. I don't need a company to know my entire life's history to exploit my past to deliver a targeted ad.

Post reply on HN