Live data from Hacker News

Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

gizmodo.com

71–80 of 99 posts

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#71
post #47
post #43

Earlier quoted context omitted.

Something similar happened to me years ago. In the process I sent a tar-ball. He replied with, "Please resend the attachment as industry standard ZIPFILE."

At least for that one, it can ostensibly explained by "In Windows tar isn't supported". But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.

I would hope that any security person, even Windows based, understands what a .tar (or .tar.gz) is. If they don't, I'd be very worried for what else they haven't been paying attention to.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#72
EquiFax outsourced its network monitoring to ReliaQuest, and I have friend who works at ReliaQuest, so I've followed this with some interest. There is a general issue here too. Back in 2017 I wrote:

"But I don’t mean to only focus on EquiFax. I’ve seen many small companies where computer security was considered the exclusive job of the tech team. I recall a jewelry manufacturer in Richmond, Virginia, which had about 100 people, including a tech team of 3. Top management of such a company has the option to educate everyone about the importance of security, or they can just leave the task to the tech team. The tech team is often happy to gain the power granted by being in charge of such an important function. And then they implement silly rules, like forcing all passwords to change each week — minor rituals that annoy a lot while offering little real security. Real security could only come from educating the staff about the open nature of email, the importance of using encrypted communications, the importance of protecting the intellectual property of the firm. A company with 97 ignorant people and 3 security minded people can never be as secure as a company with 100 security minded people."

http://www.smashcompany.com/business/if-a-company-is-serious...

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#73
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

In a world where even Rudy Giuliani is able to become a renowned 'cyber security' expert with his own consulting firm, job titles can obviously be misleading.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#74
post #14

Earlier quoted context omitted.

> It sounds like most of these costs are just from having to finally do the things they skimped on in the first place. Source? It's not TFA. TFA only talks about legal costs in the past, and doesn't state it but implies future projections are also for legal costs. With $700MM of legal costs in 1 quarter, if that is 49% of the total (51% --most-- going to finally do the things) expenditure, that's $1.4bn in one quarte…

The article placed a general emphasis on "cybersecurity costs"; I guess it didn't really indicate what percentage was that vs. litigation, but any "cybersecurity costs" are as I described above: costs that should've already been spent before the breach and are just being forced now. Only the litigation is a true "penalty".

Absolutely, only the litigation is a penalty. The article specifically and explicitly stated, $700MM in legal costs.

> Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone,

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#75

Hey Hacker News, I am Victor, the CTO of Truework ( https://www.truework.com ), a startup providing an alternative to Equifax / TheWorkNumber. We are working to change the way employment & income information is shared by employers with a more privacy focused approach where you, as an employee, decide if you want to give the information with the requester. I started this company after I found out that Equifax shared m…

So yet another company vying for personal data on millions of people, and making a business model out of it. Great, just what the world needs. (Not.)

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#76

Hey Hacker News, I am Victor, the CTO of Truework ( https://www.truework.com ), a startup providing an alternative to Equifax / TheWorkNumber. We are working to change the way employment & income information is shared by employers with a more privacy focused approach where you, as an employee, decide if you want to give the information with the requester. I started this company after I found out that Equifax shared m…

So yet another company vying for personal data on millions of people, and making a business model out of it. Great, just what the world needs. (Not.)

You're not wrong, companies can add as much security as they like but there will still be breaches, root cause is them having the data in the first place.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#79
post #49
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

That guy still works at Panera and guess where he worked prior as Sr Director of Security Operations... Equifax! https://www.linkedin.com/in/mike-gustavison-b020426/

Failing upwards at its finest.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#80
post #47
post #43

Earlier quoted context omitted.

Something similar happened to me years ago. In the process I sent a tar-ball. He replied with, "Please resend the attachment as industry standard ZIPFILE."

At least for that one, it can ostensibly explained by "In Windows tar isn't supported". But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.

WinZip and 7z support tgz.
Post reply on HN