Earlier quoted context omitted.
Something similar happened to me years ago. In the process I sent a tar-ball. He replied with, "Please resend the attachment as industry standard ZIPFILE."
At least for that one, it can ostensibly explained by "In Windows tar isn't supported". But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.
Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
71–80 of 99 posts
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#72"But I don’t mean to only focus on EquiFax. I’ve seen many small companies where computer security was considered the exclusive job of the tech team. I recall a jewelry manufacturer in Richmond, Virginia, which had about 100 people, including a tech team of 3. Top management of such a company has the option to educate everyone about the importance of security, or they can just leave the task to the tech team. The tech team is often happy to gain the power granted by being in charge of such an important function. And then they implement silly rules, like forcing all passwords to change each week — minor rituals that annoy a lot while offering little real security. Real security could only come from educating the staff about the open nature of email, the importance of using encrypted communications, the importance of protecting the intellectual property of the firm. A company with 97 ignorant people and 3 security minded people can never be as secure as a company with 100 security minded people."
http://www.smashcompany.com/business/if-a-company-is-serious...
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#73I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#74Earlier quoted context omitted.
> It sounds like most of these costs are just from having to finally do the things they skimped on in the first place. Source? It's not TFA. TFA only talks about legal costs in the past, and doesn't state it but implies future projections are also for legal costs. With $700MM of legal costs in 1 quarter, if that is 49% of the total (51% --most-- going to finally do the things) expenditure, that's $1.4bn in one quarte…
The article placed a general emphasis on "cybersecurity costs"; I guess it didn't really indicate what percentage was that vs. litigation, but any "cybersecurity costs" are as I described above: costs that should've already been spent before the breach and are just being forced now. Only the litigation is a true "penalty".
> Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone,
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#75Hey Hacker News, I am Victor, the CTO of Truework ( https://www.truework.com ), a startup providing an alternative to Equifax / TheWorkNumber. We are working to change the way employment & income information is shared by employers with a more privacy focused approach where you, as an employee, decide if you want to give the information with the requester. I started this company after I found out that Equifax shared m…
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#76Hey Hacker News, I am Victor, the CTO of Truework ( https://www.truework.com ), a startup providing an alternative to Equifax / TheWorkNumber. We are working to change the way employment & income information is shared by employers with a more privacy focused approach where you, as an employee, decide if you want to give the information with the requester. I started this company after I found out that Equifax shared m…
So yet another company vying for personal data on millions of people, and making a business model out of it. Great, just what the world needs. (Not.)
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#77Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#78Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#79I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
That guy still works at Panera and guess where he worked prior as Sr Director of Security Operations... Equifax! https://www.linkedin.com/in/mike-gustavison-b020426/
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#80Earlier quoted context omitted.
Something similar happened to me years ago. In the process I sent a tar-ball. He replied with, "Please resend the attachment as industry standard ZIPFILE."
At least for that one, it can ostensibly explained by "In Windows tar isn't supported". But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.