Live data from Hacker News

First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

krebsonsecurity.com

11–20 of 171 posts

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#11
post #7

>At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information. is such a meme. Things will continue this way until there are serious repercussions for entities carelessly handling data.

There was a repercussion a couple of days ago actually for Equifax. But yeah, maybe not serious enough to matter that much, I'm not sure what the outcome will be.

https://www.msn.com/en-us/finance/markets/moodys-cuts-equifa...

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#12
I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall.

Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#13
At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already.

The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#14

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

Unless they get punished or lose all their customers how is it a liability?

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#15

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

Only if there are laws making it a liability, since investors don't seem to care much in the long term.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#16

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

While everyone here says "Oh that's terrible!" the market says "Oh that's terr-SQUIRREL" and then forgets it ever happened. Additionally, no appropriate fines have been levied nor jail time handed out for this sort of thing - right now the sane approach (money wise) is just occasionally have a breech and offer up an apology.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#17

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

I wonder if we should take mandatory breach reporting a step further too and require them to list all security vendor products and services that were in place at the time of the breach.

Should security solution vendors be held to account for failing to live up to the bold claims they make?

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#18
post #12

I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.

I've seen Retail stores with revenues in the 10s of billions using Telnet for the POS clients in 2019. They also used FTP glaore and were worried about the security of cloud. :)

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#19
post #2

It seems that the stock price (under the ticker FAF) hasn't suffered very much. This was revealed on 5/19, and the response has been tepid.There isn't likely going to be very much backlash on the stock, unfortunately.

The breach was revealed 6 minutes before I posted this. First on Twitter, then here.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#20
post #12

I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.

I did EDI work for several major national and international companies you've definitely heard of. This is all too common, we're talking about millions of dollars of transactions per day flowing over insecure FTP sitting on the internet. VANs, originally used dial-up modems to deliver EDI, now they often use insecure FTP.

A few brave companies have tried to put their FTP systems behind VPNs, but the momentum is hard to overcome. What is more popular is firewall rules that only allow large blocks of IPs owned by other vendors they deal with. It is good in theory, until you see how large/diverse some of these blocks are (e.g. all of AWS's Eastern data center).

It was a very loud wake-up call seeing what inter-business stuff looked like. It is the wild west or a flashback to the 1990s security wise.

Post reply on HN