Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

51–60 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#51
post #15
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

The UK is a special case and will not be "Europe" for long besides. Homogenisation of rules can take a while, especially when there is a cultural aversion to them. In this case I'd say there simply has not been enough time for this to happen.

England will not be less a part of Europe just because she leaves the EU. The EU was never perfectly cohesive to start with [0], and is made up of extremely disparate nations and cultures. Plus, England never adopted the Euro (which is probably for good reason, seeing as interest rates are now even further down because the ECB can't properly conduct monetary policy).

The EU was never comparable to, say, America in terms of unity. Europe had too much history for it to work perfectly - every one was on what had been at some point some one else's land.

[0] https://europedirectemn.files.wordpress.com/2018/02/treaties...

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#52
post #39
post #19

Earlier quoted context omitted.

One of many basic cultural differences between the UK and the EU. In the EU you must give up your biometrics (fingerprint) by law. Doesn't surprise me that they are leaving.

I think surveillance techniques and invasion of privacy are often spearheaded by the UK. I remember the CCTV cameras where everywhere long before other countries leveraged them at that scale.

Then great for the EU. God willing, y'all will roll back some of that stuff if she leaves.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#53
post #23

Earlier quoted context omitted.

For many, it's a goal to avoid having a national ID, for privacy-from-the-government reasons. The ACLU has a decent writeup about the issue: https://www.aclu.org/other/5-problems-national-id-cards

Similar to constant surveillance, the psychological implications of mandatory ID are horrifying. It tips the scale from "You are born free, but you must fulfill certain obligations to cooperate with others" to "You exist first and foremost through the lens of the government. You are not permitted to live outside the bureaucratic abstraction of you."

Well then easy solution: you refrain from opting in into personal ID cards, but you're responsible for all fraudular and other activity that is done under your name and could have been prevented by having an ID card lock down your identity.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#54
There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money.

You should worry about lightning strikes and like solar flares disrupting your business before you worry about cyber security. Why should any enterprise risk manager waste their time on an issue that has no consequences?

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#55
post #51
post #15

Earlier quoted context omitted.

The UK is a special case and will not be "Europe" for long besides. Homogenisation of rules can take a while, especially when there is a cultural aversion to them. In this case I'd say there simply has not been enough time for this to happen.

England will not be less a part of Europe just because she leaves the EU. The EU was never perfectly cohesive to start with [0], and is made up of extremely disparate nations and cultures. Plus, England never adopted the Euro (which is probably for good reason, seeing as interest rates are now even further down because the ECB can't properly conduct monetary policy). The EU was never comparable to, say, America in te…

"The EU was never perfectly cohesive to start with"

You could say that about the UK - which lost a significant chunk last century and could well lose rather more this century.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#56
post #44

Earlier quoted context omitted.

Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked. If they had fallen victim to some undisclosed zero-day, I’d feel bad for them - but in this case it appears to be misconfigured VPC SGs. Their error. Inadequate processes. We are also al…

> Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked. If the system was designed by humans, it can be hacked.

Especially if the bad guy used to work for your vendor.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#57

Earlier quoted context omitted.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…

This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?

Problem is, executives don't understand those things. Of course it's very simple to point a finger at them, but they rarely are tech savvy, and they are there to run the company, not micromanage every decision every department makes.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#58
post #50

What guarantees does Amazon sell to AWS clients regarding the security of their data?

From all reports, it was caused by an internal Capital One employee and was allowed due to misconfiguration on Capital One’s side.

AWS preaches the “Shared Security Model” and emphasizes what it is responsible for and what you are responsible for.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#59

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Is it the same for small and medium sized company though? We spend quite a lot on infosec with the premise that a breach could put us out of business since we can't afford to tarnish our reputation and loose key clients.

Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and banks still need the credit score and there aren't much competition in that sector.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#60
post #45
post #34

Earlier quoted context omitted.

For which to get on you need an address to live at. For which to get one, you need a bank account (at least, but in 99.9% cases this alone is not enough), otherwise no agency is going to give rent you a house.

> For which to get on you need an address to live at. For which to get one, you need a bank account (at least, but in 99.9% cases this alone is not enough), otherwise no agency is going to give rent you a house. At what age do you become eligible for the electoral roll? At least in the states most people register to vote before they leave the house of their parents.

Can't find a quick answer on gov.uk, but I somewhat loosely recall that they let you register when you're 16.
Post reply on HN