I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…
Prosecutor discretion exists. Furthermore, AFAIK (IANAL, especially not a US criminal justice lawyer), US sentencing guidelines take into account first-party financial damages (low for CapitalOne) not diffuse third-party damages of the kind suffered that will be suffered by the 100M people whose PII was lost.
Capital One’s breach was inevitable, because we did nothing after Equifax
31–40 of 161 posts
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#32Earlier quoted context omitted.
Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…
This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#33Earlier quoted context omitted.
Prosecutor discretion exists. Furthermore, AFAIK (IANAL, especially not a US criminal justice lawyer), US sentencing guidelines take into account first-party financial damages (low for CapitalOne) not diffuse third-party damages of the kind suffered that will be suffered by the 100M people whose PII was lost.
CapitalOne disclosed that this hack is going to cost them between $100mm and $150mm, which is a lot more than JSTOR would have lost from Aaron Swartz's "hack" of academic humanities papers.
If they had fallen victim to some undisclosed zero-day, I’d feel bad for them - but in this case it appears to be misconfigured VPC SGs. Their error. Inadequate processes.
We are also all labouring under the assumption that she was the only person to make off with this data.
I’m willing to bet that she’s just the first one daft enough to talk about it.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#34Earlier quoted context omitted.
But your identity is verified through some means when opening an account, even if there is no unique document, no? Example https://www.tsb.co.uk/current-accounts/faqs/identity/
Yes it is. Electoral roll.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#35Earlier quoted context omitted.
Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…
This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#36"we did nothing" Who? These companies get sued, that is a reaction. Congress? Well if you make a law twice as illegal, I'm sure that will make it stop /s. No one wants to be hacked, let's not pretend there is no fallout from ignoring security.
Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#37Earlier quoted context omitted.
CapitalOne disclosed that this hack is going to cost them between $100mm and $150mm, which is a lot more than JSTOR would have lost from Aaron Swartz's "hack" of academic humanities papers.
Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked. If they had fallen victim to some undisclosed zero-day, I’d feel bad for them - but in this case it appears to be misconfigured VPC SGs. Their error. Inadequate processes. We are also al…
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#38Earlier quoted context omitted.
That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.
One of many basic cultural differences between the UK and the EU. In the EU you must give up your biometrics (fingerprint) by law. Doesn't surprise me that they are leaving.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#39Earlier quoted context omitted.
That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.
One of many basic cultural differences between the UK and the EU. In the EU you must give up your biometrics (fingerprint) by law. Doesn't surprise me that they are leaving.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#40Any single IT system is hackable and will eventually be hacked. The probability that an adversary will be able to hack multiple, independent systems is much lower though, and would in many cases prevent data breaches like this one.