Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

21–30 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#22

Wasn't this a private S3 bucket and she somehow hacked permission access? Anyone know the full details of how this came to happen? As for mitigation, does S3 encryption happen at the user access level (GET) or S3 system level. Basically, does each GET call pass in the decryption key? This means an attacker needs another piece of information. More encryption wouldn't hurt here. This goes for Equifax too.

I'll preface this by saying that I haven't seen any official resources confirming that it was an S3 bucket issue (although the statement from hacker mentioned releasing "buckets" so it very well could be). S3 provides server side encryption that encrypts the files at rest. This is done entirely on the server side and does not require any additional keys from the client. However, it is possible to do your own file enc…

That's not a "full disclosure", that's spam.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#23

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

> If you dont have a drivers license and other things to show you shouldnt get a credit card. In Europe everyone has to possess a personal ID card or a proper passport, and it is required to be presented to the bank agent (or a verification service). Yes, we do have some problems with faked ID cards and lately by fraudulent video identification, but still - not remotely comparable to the laughable "security" in the U…

For many, it's a goal to avoid having a national ID, for privacy-from-the-government reasons. The ACLU has a decent writeup about the issue: https://www.aclu.org/other/5-problems-national-id-cards

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#24
post #19
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

One of many basic cultural differences between the UK and the EU. In the EU you must give up your biometrics (fingerprint) by law. Doesn't surprise me that they are leaving.

> In the EU you must give up your biometrics (fingerprint) by law

Generic and incorrect statement

Also, I'm not an UK citizen and I'm forced to give up my biometrics (face) whenever flying out of an UK airport. Or when flying into the US.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#25
post #17

Not even close to the same. Granted a misconfigured firewall is surprisingly close to data with no AuthZ/AuthN but the Equifax breach was an operation. This should be punished but the level of ignorance from both sides highlight just how immature the community is and how little concern we have in handling PII. Thermodynamics....make the path of least resistance more secure. I feel laws find that by following the mone…

It's actually a lot harder than you'd imagine to break into security considering how much outrage and demand there seems to be in the press and on forums.

Maybe this WAF wasn't the greatest software though. Simply buying something and squeezing it into your tech stack isn't enough. You have to know how it works or it could be the thing that gives a foothold to an attacker.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#26
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

But your identity is verified through some means when opening an account, even if there is no unique document, no? Example https://www.tsb.co.uk/current-accounts/faqs/identity/

Yes it is. Electoral roll.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#27
post #22

Earlier quoted context omitted.

I'll preface this by saying that I haven't seen any official resources confirming that it was an S3 bucket issue (although the statement from hacker mentioned releasing "buckets" so it very well could be). S3 provides server side encryption that encrypts the files at rest. This is done entirely on the server side and does not require any additional keys from the client. However, it is possible to do your own file enc…

That's not a "full disclosure", that's spam.

I added that because CapitalOne has an open source tool that has similar functionally, but point taken and post edited.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#28

Earlier quoted context omitted.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…

Utopia solutions aren't really helpful for ideas. It's great if companies had unlimited resources to spend on security, and didn't screw their customers with fees. Let me remind you, even Apple had their phone hacked. More laws won't make mistakes go away.

It doesn't take unlimited resources to destroy sensitive transient information past its time. The opposite really.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#29
post #19
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

One of many basic cultural differences between the UK and the EU. In the EU you must give up your biometrics (fingerprint) by law. Doesn't surprise me that they are leaving.

Please show which law this is, I've never had to give my biometrics to anyone but the US government when visiting there.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#30
post #15
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

The UK is a special case and will not be "Europe" for long besides. Homogenisation of rules can take a while, especially when there is a cultural aversion to them. In this case I'd say there simply has not been enough time for this to happen.

Barring a rather spectacular feat of engineering, the UK won't be relocating itself from Europe any time soon (much to the chagrin of those who seem to want to plonk us next to Singapore ...)
Post reply on HN