Live data from Hacker News

First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

krebsonsecurity.com

151–160 of 171 posts

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#152

Earlier quoted context omitted.

No, nothing wrong with it intrinsically. But if UUIDs were used instead, the lack of authentication or authorization checks wouldn't be as catastrophic. That would be somewhat comparable to having a reset password token which doesn't expire. Still bad, but not as bad. The other commenter's point about leaking information is also correct. In the finance industry one of the basic tricks to obtaining alternative data is…

Nice. This reminds me of the German Tank problem in WWII, where the allies used samples of serial numbers from captured nazi tanks, to estimate their population. The tanks and their parts used sequential serial numbers. It could also be used to determine production rates too I guess. The idea pre-dates web APIs many decades :-) See https://en.m.wikipedia.org/wiki/German_tank_problem

That's how you can get a self-referencing tweet as well. https://twitter.com/spoonhenge/status/2878871344

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#153
I see a lot of comments on sequential as the issue. Really is that the issue?

Not the fact that John Doe can get to John Doe2 stuff without authenticating? WTF

Sequential or not if no auth I can run a scanner and get it all so what the hell does that have to do with the price of tea in China?

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#154
post #117

A lot of discussion on technical side, but not from organisational. How could audit, both internal and external, not find this? 2003 to today is 16 years. Audit is a last line of defence and certainly not to be relied on upon as a buddy to catch your errors. But... how? This is a major financial institution in the most developed country in the world (the clue's in the name). It should subscribe to the the highest int…

You can access documents all the way back to 2003. That doesn’t necessarily mean that this hole has existed that long.

Very good point.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#155

Earlier quoted context omitted.

I'm usually an uncooperative bastard at times like this. I ask them what their purpose is in retaining a copy of my identity document, and I ask for their privacy policy. When I'm travelling for work and a hotel asks I simply say no, and remind them I can lodge a complaint with our corporate travel provider that will have them delisted for future business; usually they come to their senses. For overseas travel (where…

Where do they ask you for a copy of your ID? I've never had that happen to me at a hotel.

It's because of credit card fraud usually, they want it to prove to credit providers that the actual card holder was present, and if not, exactly who. And I've been asked in countries across the first world, though I haven't been keeping specific note of when.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#156

Earlier quoted context omitted.

I don't know what 1.whatever is. Yes, I've worked for supercorps, mainly financials, and I have a responsibility to ensure customer and employee data are managed responsibly. It is important to escalate what doesn't seem right. Sometimes that means email after email after email (written record) and that if it still doesn't smell right to keep pushing. Ops was a strange place, but 500 emails per day is no longer a cha…

Clarification on 1/one — in my experience big co is naturally striving for synergies and often target “IT” as it’s seemingly an obvious candidate. These projects often bare a description such as “ProgramOne”, “Platform1” or 1SomethingAwesome, and is of a “bite of more than you can chew” character. At least at three of class leading companies I’ve worked, all with 90.000+ employees. It’s just my disillusionment shinin…

> the future holds a merger of tech with business

Completely agree. And regulators are pushing for this. When.. in retail and SME banking and financial services the future is here, in Europe, but has yet to gain traction and public trust but that's coming quickly. That will be 5 years, change takes time, a long journey for VC money but not too long, they will see returns.

Asia will be slow. NA perhaps slower still. AU might pick up the ball but NZ will be faster if they choose. SG will lag HK because of technical debt in SG. I'm Asia based, not much idea on South America. South Asia are hand-tied by regulation, mainly currency, restrictions, the above regulators will be providing markets with the best retail and SME financial products. A hot place to be, Europe probably hotter coz PSD2.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#158

A lot of discussion on technical side, but not from organisational. How could audit, both internal and external, not find this? 2003 to today is 16 years. Audit is a last line of defence and certainly not to be relied on upon as a buddy to catch your errors. But... how? This is a major financial institution in the most developed country in the world (the clue's in the name). It should subscribe to the the highest int…

You know what's a great incentive to actually care about this stuff? Legal consequences for not caring about it. Anyone conceivably responsible for ignoring the developer's complaint should be on trial right now.

As an American resident in Europe, I have to wonder what liability they face under GDPR.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#159

Earlier quoted context omitted.

Clarification on 1/one — in my experience big co is naturally striving for synergies and often target “IT” as it’s seemingly an obvious candidate. These projects often bare a description such as “ProgramOne”, “Platform1” or 1SomethingAwesome, and is of a “bite of more than you can chew” character. At least at three of class leading companies I’ve worked, all with 90.000+ employees. It’s just my disillusionment shinin…

> the future holds a merger of tech with business Completely agree. And regulators are pushing for this. When.. in retail and SME banking and financial services the future is here, in Europe, but has yet to gain traction and public trust but that's coming quickly. That will be 5 years, change takes time, a long journey for VC money but not too long, they will see returns. Asia will be slow. NA perhaps slower still. A…

My feeling is that at some places the effects is still somewhat underestimated.

There’s probably 90% lower hanging fruit than blockchain, if you know what I mean.

Throwing inventive projects at failing orgs will most likely fall flat.

I understand many of the challenges though, and no true recipe for change exists.

The closest I can think about is “letting go”.

I mean, you have people hired for a reason! If you don’t trust them doing their thing, who’s the one hiring them?

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#160
post #84

Earlier quoted context omitted.

that is a good idea but most of the time I need to hand over my actual ID, and not just a scan of it

I'm usually an uncooperative bastard at times like this. I ask them what their purpose is in retaining a copy of my identity document, and I ask for their privacy policy. When I'm travelling for work and a hotel asks I simply say no, and remind them I can lodge a complaint with our corporate travel provider that will have them delisted for future business; usually they come to their senses. For overseas travel (where…

I used to be uncooperative too but in the end, I usually have to still give it (or go somewhere else)
Post reply on HN