Live data from Hacker News

Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

gizmodo.com

91–99 of 99 posts

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#91
post #50
post #2

> Moody’s downgraded Equifax from a “stable” to a “negative” outlook > Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone > And the lawsuits will keep coming: In January, an Atlanta judge denied Equifax’s attempts to dismiss class-actions filed against the company. Looks like there are real consequences to losing data on half of all Americans

Will any of the individuals responsible face direct consequences for their actions? Or, will the cost of their mistakes be borne entirely by shareholders?

The shareholders should bear the consequences of failure, just as they reap the rewards of success.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#92
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.

I think it's the same everywhere. I work in finance, after 5 years of working out of college in almost convinced that incompetence is a requirement for senior management positions. That and ass kissing and the ability to twist facts

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#93
post #2

> Moody’s downgraded Equifax from a “stable” to a “negative” outlook > Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone > And the lawsuits will keep coming: In January, an Atlanta judge denied Equifax’s attempts to dismiss class-actions filed against the company. Looks like there are real consequences to losing data on half of all Americans

But not because of anything Congress did.

If the system works as-is, does Congress need to do anything?

Ideally, I think that we'd want the federal Congress and the individual state legislatures being reflective, making prospective decisions which anticipate future events and impose the correct structure to deal with them, rather than retrospectively doing something in order to be seen to do something.

But no-one ever got elected on a platform of 'my predecessors did a great job; I'm going to play some golf!'

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#94
post #26
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…

In my last job I was responsible for onboarding b2b clients to send us hr data through sftp with key authentication. We also recommended they encrypt with our public pgp key and sign with their private key. Trying to explain the difference between ssh keys and pgp/gpg keys took up a good 20% of my time some weeks. Often, I was talking to tech companies, or companies with a reputation for technology... I don't think the majority of Windows admins understand public/private keys.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#95
post #80
post #47

Earlier quoted context omitted.

At least for that one, it can ostensibly explained by "In Windows tar isn't supported". But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.

WinZip and 7z support tgz.

By default Windows handles Zip files in Explorer. Ostensibly it's fair to assume that "I don't run non-standard apps when I can avoid it" is a reasonable (if limiting) premise.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#96

Earlier quoted context omitted.

This would be funny if it wasn't so depressingly true.

We are perhaps being too cynical, it isn't quite that straight forward. I hear you also need to wear the right tie and buy the correct pair of expensive shoes.

Also your uncle knows the manager

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#97
post #39

Equifax: where you’re a customer whether you wanted to be or not.

Not quite right, rather "Equifax: where you're our product whether you wanted to be or not."

I stand corrected :)

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#98
In the long run I don't think anything will change at Equifax. At worst, it will get absorbed by another company, re-branded, and no one will know where the former Equifax has gone. At best, it will get disbanded and its executives put in prison.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#99
I saw so many good review about this great hacker and I just can't stop sharing the Gospel of this hacker (CREDIT WIZARD ) until other people enjoy his amazing service. He's one of a kind. He hacks anything and everything.I was looking to repair my credit, but I have went through more than a few individuals whom stated that they could and have my funds without a outcome.I got a review from a forum about CREDI WIZARD and was wondering if this could be possible until i see my credit score increased to 800. He offers many other hacking services like credit repair and score boost, website hack, university database hack and grade change, erasing criminal records, bank accounts infiltration, GPS tracking, retrieval of lost documents, tracking stolen funds, spy your cheating spouse and so many other services I cant mention them all. Contact CREDIT WIZARD for more details at cyberwizard1995@gmail.com/ +1 662 727 5740
Post reply on HN