First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
151–160 of 171 posts
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#152Earlier quoted context omitted.
No, nothing wrong with it intrinsically. But if UUIDs were used instead, the lack of authentication or authorization checks wouldn't be as catastrophic. That would be somewhat comparable to having a reset password token which doesn't expire. Still bad, but not as bad. The other commenter's point about leaking information is also correct. In the finance industry one of the basic tricks to obtaining alternative data is…
Nice. This reminds me of the German Tank problem in WWII, where the allies used samples of serial numbers from captured nazi tanks, to estimate their population. The tanks and their parts used sequential serial numbers. It could also be used to determine production rates too I guess. The idea pre-dates web APIs many decades :-) See https://en.m.wikipedia.org/wiki/German_tank_problem
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#153Not the fact that John Doe can get to John Doe2 stuff without authenticating? WTF
Sequential or not if no auth I can run a scanner and get it all so what the hell does that have to do with the price of tea in China?
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#154A lot of discussion on technical side, but not from organisational. How could audit, both internal and external, not find this? 2003 to today is 16 years. Audit is a last line of defence and certainly not to be relied on upon as a buddy to catch your errors. But... how? This is a major financial institution in the most developed country in the world (the clue's in the name). It should subscribe to the the highest int…
You can access documents all the way back to 2003. That doesn’t necessarily mean that this hole has existed that long.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#155Earlier quoted context omitted.
I'm usually an uncooperative bastard at times like this. I ask them what their purpose is in retaining a copy of my identity document, and I ask for their privacy policy. When I'm travelling for work and a hotel asks I simply say no, and remind them I can lodge a complaint with our corporate travel provider that will have them delisted for future business; usually they come to their senses. For overseas travel (where…
Where do they ask you for a copy of your ID? I've never had that happen to me at a hotel.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#156Earlier quoted context omitted.
I don't know what 1.whatever is. Yes, I've worked for supercorps, mainly financials, and I have a responsibility to ensure customer and employee data are managed responsibly. It is important to escalate what doesn't seem right. Sometimes that means email after email after email (written record) and that if it still doesn't smell right to keep pushing. Ops was a strange place, but 500 emails per day is no longer a cha…
Clarification on 1/one — in my experience big co is naturally striving for synergies and often target “IT” as it’s seemingly an obvious candidate. These projects often bare a description such as “ProgramOne”, “Platform1” or 1SomethingAwesome, and is of a “bite of more than you can chew” character. At least at three of class leading companies I’ve worked, all with 90.000+ employees. It’s just my disillusionment shinin…
Completely agree. And regulators are pushing for this. When.. in retail and SME banking and financial services the future is here, in Europe, but has yet to gain traction and public trust but that's coming quickly. That will be 5 years, change takes time, a long journey for VC money but not too long, they will see returns.
Asia will be slow. NA perhaps slower still. AU might pick up the ball but NZ will be faster if they choose. SG will lag HK because of technical debt in SG. I'm Asia based, not much idea on South America. South Asia are hand-tied by regulation, mainly currency, restrictions, the above regulators will be providing markets with the best retail and SME financial products. A hot place to be, Europe probably hotter coz PSD2.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#157Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#158A lot of discussion on technical side, but not from organisational. How could audit, both internal and external, not find this? 2003 to today is 16 years. Audit is a last line of defence and certainly not to be relied on upon as a buddy to catch your errors. But... how? This is a major financial institution in the most developed country in the world (the clue's in the name). It should subscribe to the the highest int…
You know what's a great incentive to actually care about this stuff? Legal consequences for not caring about it. Anyone conceivably responsible for ignoring the developer's complaint should be on trial right now.
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#159Earlier quoted context omitted.
Clarification on 1/one — in my experience big co is naturally striving for synergies and often target “IT” as it’s seemingly an obvious candidate. These projects often bare a description such as “ProgramOne”, “Platform1” or 1SomethingAwesome, and is of a “bite of more than you can chew” character. At least at three of class leading companies I’ve worked, all with 90.000+ employees. It’s just my disillusionment shinin…
> the future holds a merger of tech with business Completely agree. And regulators are pushing for this. When.. in retail and SME banking and financial services the future is here, in Europe, but has yet to gain traction and public trust but that's coming quickly. That will be 5 years, change takes time, a long journey for VC money but not too long, they will see returns. Asia will be slow. NA perhaps slower still. A…
There’s probably 90% lower hanging fruit than blockchain, if you know what I mean.
Throwing inventive projects at failing orgs will most likely fall flat.
I understand many of the challenges though, and no true recipe for change exists.
The closest I can think about is “letting go”.
I mean, you have people hired for a reason! If you don’t trust them doing their thing, who’s the one hiring them?
Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records
#160Earlier quoted context omitted.
that is a good idea but most of the time I need to hand over my actual ID, and not just a scan of it
I'm usually an uncooperative bastard at times like this. I ask them what their purpose is in retaining a copy of my identity document, and I ask for their privacy policy. When I'm travelling for work and a hotel asks I simply say no, and remind them I can lodge a complaint with our corporate travel provider that will have them delisted for future business; usually they come to their senses. For overseas travel (where…