I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.
I've seen Retail stores with revenues in the 10s of billions using Telnet for the POS clients in 2019. They also used FTP glaore and were worried about the security of cloud. :)
First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
21–30 of 171 posts
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#221. Using sequentially incremented integer sequences as object IDs, and
2. Failing to protect sensitive data using some kind of authentication and authorization check.
This is becoming a trend with data breaches. Several of Krebs' other reports on behalf of security researchers were originally identified by (trivially) walking across object IDs on public URLs.
My cynical take is that Krebs couldn't go public before this afternoon because First American wanted it to hit the news at an opportune time, then get ahead of it with their own messaging. Krebs got in touch with First American on Monday May 19th. The story is only just breaking now on a Friday afternoon at 5 pm; markets are conveniently closed for the weekend.
I expect them to issue a hollow PR statement about valuing security despite being unable to act on security reports until an investigative journalist threatens to go public.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#23I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#24>At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information. is such a meme. Things will continue this way until there are serious repercussions for entities carelessly handling data.
> We are currently evaluating what effect, if any, this had on the security of customer information.
It's downright dishonest to even say "if any": they were presented with concrete examples of leaking customer information; they don't get to wonder whether it had an effect on their security anymore.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#25It seems that the stock price (under the ticker FAF) hasn't suffered very much. This was revealed on 5/19, and the response has been tepid.There isn't likely going to be very much backlash on the stock, unfortunately.
I don't think there will be, we're well into "breach fatigue" territory now, and here there's not even currently any evidence of malicious use. Unless/until this breach results in a large financial hit to the company (possibly via a class action suit) I doubt it'll have any impact and I'm not even sure a class action suit could show damages without evidence of misuse.
I suspect this is going to hit First American pretty hard.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#26I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall. Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.
Depending on how weak those credentials were, this sounds like something you should report to Krebs as well.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#27At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.
That's my line :):
"It forces you to think about data as a liability, rather than an asset and that particular mindset is a good one to have when you are dealing with end user data."
https://jacquesmattheij.com/gdpr-hysteria-part-ii-nuts-and-b...
It stood the test of time rather well. Now we see a US push for a similar law and articles such as this one hopefully will cause that to arrive sooner rather than later.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#28At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.
While everyone here says "Oh that's terrible!" the market says "Oh that's terr-SQUIRREL" and then forgets it ever happened. Additionally, no appropriate fines have been levied nor jail time handed out for this sort of thing - right now the sane approach (money wise) is just occasionally have a breech and offer up an apology.
https://www.darkreading.com/attacks-breaches/moodys-downgrad...
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#29At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.
I wonder if we should take mandatory breach reporting a step further too and require them to list all security vendor products and services that were in place at the time of the breach. Should security solution vendors be held to account for failing to live up to the bold claims they make?
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#30At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.
> At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. That's my line :): "It forces you to think about data as a liability, rather than an asset and that particular mindset is a good one to have when you are dealing with end user data." https://jacquesmattheij.com/gdpr-hysteria-part-ii-nuts-and-b... It stood the test of time rather well. Now we see a…