Live data from Hacker News

First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

krebsonsecurity.com

21–30 of 171 posts

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#21
post #12

I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.

I've seen Retail stores with revenues in the 10s of billions using Telnet for the POS clients in 2019. They also used FTP glaore and were worried about the security of cloud. :)

Ditto. I've seen the same thing going on at an investment bank processing $350 billion / day in transactions.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#22
Yet another security vulnerability caused by:

1. Using sequentially incremented integer sequences as object IDs, and

2. Failing to protect sensitive data using some kind of authentication and authorization check.

This is becoming a trend with data breaches. Several of Krebs' other reports on behalf of security researchers were originally identified by (trivially) walking across object IDs on public URLs.

My cynical take is that Krebs couldn't go public before this afternoon because First American wanted it to hit the news at an opportune time, then get ahead of it with their own messaging. Krebs got in touch with First American on Monday May 19th. The story is only just breaking now on a Friday afternoon at 5 pm; markets are conveniently closed for the weekend.

I expect them to issue a hollow PR statement about valuing security despite being unable to act on security reports until an investigative journalist threatens to go public.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#23
post #12

I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.

Depending on how weak those credentials were, this sounds like something you should report to Krebs as well.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#24
post #7

>At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information. is such a meme. Things will continue this way until there are serious repercussions for entities carelessly handling data.

The next sentence too:

> We are currently evaluating what effect, if any, this had on the security of customer information.

It's downright dishonest to even say "if any": they were presented with concrete examples of leaking customer information; they don't get to wonder whether it had an effect on their security anymore.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#25
post #2

It seems that the stock price (under the ticker FAF) hasn't suffered very much. This was revealed on 5/19, and the response has been tepid.There isn't likely going to be very much backlash on the stock, unfortunately.

I don't think there will be, we're well into "breach fatigue" territory now, and here there's not even currently any evidence of malicious use. Unless/until this breach results in a large financial hit to the company (possibly via a class action suit) I doubt it'll have any impact and I'm not even sure a class action suit could show damages without evidence of misuse.

Equifax's costs as a result of their breach have exceeded $1 billion now, and Moody's downgraded them a couple of days ago.

I suspect this is going to hit First American pretty hard.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#26
post #12

I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.

Depending on how weak those credentials were, this sounds like something you should report to Krebs as well.

I'll bet client4 is already breaking an NDA or two just by posting this.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#27

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

> At some point people will realise that holding large quantities of sensitive information is a liability, not an asset.

That's my line :):

"It forces you to think about data as a liability, rather than an asset and that particular mindset is a good one to have when you are dealing with end user data."

https://jacquesmattheij.com/gdpr-hysteria-part-ii-nuts-and-b...

It stood the test of time rather well. Now we see a US push for a similar law and articles such as this one hopefully will cause that to arrive sooner rather than later.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#28
post #16

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

While everyone here says "Oh that's terrible!" the market says "Oh that's terr-SQUIRREL" and then forgets it ever happened. Additionally, no appropriate fines have been levied nor jail time handed out for this sort of thing - right now the sane approach (money wise) is just occasionally have a breech and offer up an apology.

That's what everyone (including myself) said after Equifax but just this week their credit rating was downgraded by Moody's:

https://www.darkreading.com/attacks-breaches/moodys-downgrad...

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#29
post #17

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

I wonder if we should take mandatory breach reporting a step further too and require them to list all security vendor products and services that were in place at the time of the breach. Should security solution vendors be held to account for failing to live up to the bold claims they make?

Depends on how they sold it. Did they sell tools, or tools plus configuration services and consulting?

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#30

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

> At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. That's my line :): "It forces you to think about data as a liability, rather than an asset and that particular mindset is a good one to have when you are dealing with end user data." https://jacquesmattheij.com/gdpr-hysteria-part-ii-nuts-and-b... It stood the test of time rather well. Now we see a…

This company is dealing in financial transaction data. Someone needs to hold it, and it can be deleted (especially when someone asks for it). I don't see how this particular situation advances your position.
Post reply on HN