Live data from Hacker News

Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

gizmodo.com

21–30 of 99 posts

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#21
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

How do people so dangerously incompetent get hired into these roles?

Edit: My question and the replies are incredibly depressing as an infosec practitioner.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#22

Earlier quoted context omitted.

But not because of anything Congress did.

I would have liked Congress to do more too, but is this relevant here?

In a thread discussing Equifax's data breach, costs, and liabilities? Where would it be more relevant?

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#24
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.

The volume of people in the security world with near 0 basic knowledge is pretty shocking, but common.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#25
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.

"Experience"

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#26
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

The initial email exchange is indeed a sight to see, so I transcribed the text in the image:

---------

Hello Mike et al

Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number and the last four digits of their saved credit card number. Moreover, the users are easily enumerable which means an attacker can crawl through the records.

I can provide the specific details of the vulnerability over email once you respond, but if you prefer (for more security), I can also encrypt the information with a PGP key you provide me. Alternatively we can hop on a phone call.

Best Regards, Dylan Houlihan

--------------

Dylan

My team received your emails however it was very suspicious and appeared scam in nature therefore was ignored. If this is a sales tactic I would highly recommend a better approach as demanding a PGP key would not be a good way to start off. As a security professional you should be aware that any organization that has a security practice would never respond to a request like the one you sent. I am willing to discuss whatever vulnerabilities you believe you have found but I will not be duped, demanded for restitution/bounty or listen to a sales pitch.

Regards, Mike

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#27
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.

The people making the decisions about who to hire have even less technical expertise.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#28
post #26
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…

I was almost expecting something like this to follow:

I am certainly not authorized to give away the public key but I have a private one that I would share if necessary.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#29
post #15
post #4

How these guys are still in business and still collecting financial data on US citizens frankly baffles me.

It is really, really hard to get in trouble in the United States if you have a lot of money and some friends in Washington.

And all it takes to have friends in Washington is some money.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#30
post #7

Another situation of too big to fail? I sure hope not. Why are they still in business? Any worthy regulation of any type would have shut them down already no?

> Why are they still in business? Lawsuits are progressing. It's possible legal costs (plus the accompanying reputational damage) will eventually force Equifax into bankruptcy. (I, for example, refuse to open credit lines if they require an Equifax credit check.) At the end of the day, you can't just kill companies because you don't like them. We don't have general data protection laws with heavy penalties in the Uni…

Going to enjoy the inevitable dumpster fires because of Equifax suddenly becoming unreachable.
Post reply on HN