> Moody’s downgraded Equifax from a “stable” to a “negative” outlook > Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone > And the lawsuits will keep coming: In January, an Atlanta judge denied Equifax’s attempts to dismiss class-actions filed against the company. Looks like there are real consequences to losing data on half of all Americans
Will any of the individuals responsible face direct consequences for their actions? Or, will the cost of their mistakes be borne entirely by shareholders?
Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
91–99 of 99 posts
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#92I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#93> Moody’s downgraded Equifax from a “stable” to a “negative” outlook > Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone > And the lawsuits will keep coming: In January, an Atlanta judge denied Equifax’s attempts to dismiss class-actions filed against the company. Looks like there are real consequences to losing data on half of all Americans
But not because of anything Congress did.
Ideally, I think that we'd want the federal Congress and the individual state legislatures being reflective, making prospective decisions which anticipate future events and impose the correct structure to deal with them, rather than retrospectively doing something in order to be seen to do something.
But no-one ever got elected on a platform of 'my predecessors did a great job; I'm going to play some golf!'
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#94I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…
Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity
#95Earlier quoted context omitted.
At least for that one, it can ostensibly explained by "In Windows tar isn't supported". But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.
WinZip and 7z support tgz.