Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

41–50 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#41

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

> Can the punishment for crimes stop being absurd.

The absurd punishment was Swartz’s, and was 8 years ago. Are you saying that, out of fairness, the punishment for all future computer crimes should scale up to make this one tragic event seem more reasonable?

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#42
post #17

Not even close to the same. Granted a misconfigured firewall is surprisingly close to data with no AuthZ/AuthN but the Equifax breach was an operation. This should be punished but the level of ignorance from both sides highlight just how immature the community is and how little concern we have in handling PII. Thermodynamics....make the path of least resistance more secure. I feel laws find that by following the mone…

It's actually a lot harder than you'd imagine to break into security considering how much outrage and demand there seems to be in the press and on forums. Maybe this WAF wasn't the greatest software though. Simply buying something and squeezing it into your tech stack isn't enough. You have to know how it works or it could be the thing that gives a foothold to an attacker.

I spend a considerable amount of time pentesting. I understand it very well

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#43

Wasn't this a private S3 bucket and she somehow hacked permission access? Anyone know the full details of how this came to happen? As for mitigation, does S3 encryption happen at the user access level (GET) or S3 system level. Basically, does each GET call pass in the decryption key? This means an attacker needs another piece of information. More encryption wouldn't hurt here. This goes for Equifax too.

Basically, I gathered from the indictment that they had a 'WAF misconfiguration', which I take to be SSRF allowing her to obtain temporary AWS credentials from the metadata endpoint, which have the WAF role they talked about, which has sufficient permissions to list buckets and download files etc.

This is precisely my read as well. Could be cred disclosure through a stackdump or the like as well but most likely SSRF.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#44

Earlier quoted context omitted.

CapitalOne disclosed that this hack is going to cost them between $100mm and $150mm, which is a lot more than JSTOR would have lost from Aaron Swartz's "hack" of academic humanities papers.

Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked. If they had fallen victim to some undisclosed zero-day, I’d feel bad for them - but in this case it appears to be misconfigured VPC SGs. Their error. Inadequate processes. We are also al…

> Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked.

If the system was designed by humans, it can be hacked.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#45
post #34

Earlier quoted context omitted.

Yes it is. Electoral roll.

For which to get on you need an address to live at. For which to get one, you need a bank account (at least, but in 99.9% cases this alone is not enough), otherwise no agency is going to give rent you a house.

> For which to get on you need an address to live at. For which to get one, you need a bank account (at least, but in 99.9% cases this alone is not enough), otherwise no agency is going to give rent you a house.

At what age do you become eligible for the electoral roll? At least in the states most people register to vote before they leave the house of their parents.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#46
post #37

Earlier quoted context omitted.

Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked. If they had fallen victim to some undisclosed zero-day, I’d feel bad for them - but in this case it appears to be misconfigured VPC SGs. Their error. Inadequate processes. We are also al…

"If you properly secure your stack, you don’t get hacked." Thats absolutely not true. You do reduce the chances of being hacked and you might reduce time it takes for you to discover the breach and you will be able to contain it quicker.

You vastly reduce the chances. It’s the difference between bothering to close the bank vault’s door when you go home at night or not.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#47
post #23

Earlier quoted context omitted.

> If you dont have a drivers license and other things to show you shouldnt get a credit card. In Europe everyone has to possess a personal ID card or a proper passport, and it is required to be presented to the bank agent (or a verification service). Yes, we do have some problems with faked ID cards and lately by fraudulent video identification, but still - not remotely comparable to the laughable "security" in the U…

For many, it's a goal to avoid having a national ID, for privacy-from-the-government reasons. The ACLU has a decent writeup about the issue: https://www.aclu.org/other/5-problems-national-id-cards

Similar to constant surveillance, the psychological implications of mandatory ID are horrifying. It tips the scale from "You are born free, but you must fulfill certain obligations to cooperate with others" to "You exist first and foremost through the lens of the government. You are not permitted to live outside the bureaucratic abstraction of you."

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#48
post #6

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

Prosecutor discretion exists. Furthermore, AFAIK (IANAL, especially not a US criminal justice lawyer), US sentencing guidelines take into account first-party financial damages (low for CapitalOne) not diffuse third-party damages of the kind suffered that will be suffered by the 100M people whose PII was lost.

> Prosecutor discretion exists.

Which means she should've been held personally responsible/impeached over what she did to Swartz. But instead Obama protected her, just like he did with all of his other government criminals, as well as Bush administration's criminals, too.

"We need to move forward." and "No abuses were found." and other such BS needs to end when it comes to government criminals. No wonder more riots are popping up and the hatred towards authorities is increasing every year.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#49

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

That a corporation worth multiple billions of dollars can't keep our information secure despite one individual.

That is the message here.

IMHO, the "punishment" trajectory should aim toward Capital One. After all they are the ones who ultimately fucked up.

Frankly; Oh dear my ex-employee, or someone "trusted" who was pissed off because I/We didn't think I/We did anything to piss them off is not an admissible excuse.

Why anyone should weep for a multi-billion dollar company while crowing "throw the bitch in jail" for exposing their lacking security practices is beyond me.

Who is the criminal. A large mega-corp who could not keep their shit straight or an individual who proved their security perfectly invalid, and then told us!

Cry me a river...

Post reply on HN