Unfortunately, the federal government has no appetite for holding corporations criminally responsible for actions in this day and age. The belief in too big to fail and campaign donations are monumentally hard to overcome.
Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
41–50 of 99 posts
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#42Earlier quoted context omitted.
I would have liked Congress to do more too, but is this relevant here?
In a thread discussing Equifax's data breach, costs, and liabilities? Where would it be more relevant?
But, ideally it should have been a direct comment on this story. You replied to an unrelated statement.
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#43I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
That blog post is amazing.
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#44I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#45Earlier quoted context omitted.
The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…
reminds me of the time Oklahoma City was threatening CentoOS with calling the FBI because there website was down and they thought CentOS hacked it: https://www.theregister.co.uk/2006/03/24/tuttle_centos/ If you are in a position where you don't understand the e-mail then ASK someone who does. Or a quick google search with "PGP e-mail", wow was that so hard. The guy was probably late for a golf game or something (ok n…
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#46Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#47Earlier quoted context omitted.
That blog post is amazing.
Something similar happened to me years ago. In the process I sent a tar-ball. He replied with, "Please resend the attachment as industry standard ZIPFILE."
But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#48I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…
> demanding a PGP key would not be a good way to start off.
Oh dear god...
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#49I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#50> Moody’s downgraded Equifax from a “stable” to a “negative” outlook > Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone > And the lawsuits will keep coming: In January, an Atlanta judge denied Equifax’s attempts to dismiss class-actions filed against the company. Looks like there are real consequences to losing data on half of all Americans