Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

71–80 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#71
First American Financial Corporation is another company that appears to have been extremely naive about securing non-public personal information and didn't act until their customers went public. That wasn't even a platform security vulnerability. They were allowing unauthenticated access to their customers documents. Brian Krebs reported on 24 May that 885 million mortgage documents had been exposed. According to First American's reporting since then, they say they have narrowed that down to 32 consumers that had their information exposed and provided them with complementary credit monitoring. That's an awfully big discrepancy between the security community and company reporting.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#72

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

I 'm considering putting up a disclaimer before signing up to my sites: "Hey there, this is the internet. Even if we 're not bad people, any data you give us may be hacked and sold , publicized etc. So don't do the dumb thing and tell us your best kept secret."

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#73

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

We don't really know enough yet. My read is that Capital One was horrifically negligent, and none of the data was actually resold or used...

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#74

Earlier quoted context omitted.

The consequence is I won't use them and as much as possible others won't either. It's not the same as no consequence, but I get what you mean. The government plays so nicely with business that we shouldn't expect even a day's worth of business profits in related fines.

I am pretty sure the vast majority of people don't even know about these breaches, and even if they do it's news that passes them by quickly. Maybe a rant or two on Facebook and then onto the next thing. Almost everyone will continue to use their Capital One credit card and the company will barely see a blip in their revenue.

When the news is mainly about people dying, someone selling stolen rolodexes sounds insignificant in comparison

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#75

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Is it the same for small and medium sized company though? We spend quite a lot on infosec with the premise that a breach could put us out of business since we can't afford to tarnish our reputation and loose key clients. Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and b…

Depends on the market. Do your clients talk to each other?

In a small market with few potential customers, reputation loss could kill you. OTOH if you sell to general population, then even a scandal involving you being featured on national TV won't hurt your company directly (related lawsuits might, though).

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#76
post #6

Earlier quoted context omitted.

Prosecutor discretion exists. Furthermore, AFAIK (IANAL, especially not a US criminal justice lawyer), US sentencing guidelines take into account first-party financial damages (low for CapitalOne) not diffuse third-party damages of the kind suffered that will be suffered by the 100M people whose PII was lost.

CapitalOne disclosed that this hack is going to cost them between $100mm and $150mm, which is a lot more than JSTOR would have lost from Aaron Swartz's "hack" of academic humanities papers.

It seems likely that were the accused to be convicted, a fine will be part of the sentencing, and Capital One may opt to pursue separate civil legal remedy against the convicted person to seek damages given their cost is stated as being >$100M. Unclear to me if this somehow isn’t allowed under U.S. law because the federal prosecution may be where it all gets determined, and a civil case may be “double punishment”?

So after coming out of prison and finding a job, which is likely to be hard for a felon, and may not be highly paid, what wages they make will be garnished to pay the criminal/civil financial judgements.

For most people who’ve worked in technology, the potential punishment here would qualify as “destroying your life”. Enormous impact.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#77
post #70

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

And don't forget the recycled Red Scare neo-McCarthyism they are currently using to overturn an election. Between the twits on the left and the twits on the right, we're doomed.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#78

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

We don't really know enough yet. My read is that Capital One was horrifically negligent, and none of the data was actually resold or used...

> none of the data was actually resold or used...

Yet.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#79

Earlier quoted context omitted.

Utopia solutions aren't really helpful for ideas. It's great if companies had unlimited resources to spend on security, and didn't screw their customers with fees. Let me remind you, even Apple had their phone hacked. More laws won't make mistakes go away.

It doesn't take unlimited resources to destroy sensitive transient information past its time. The opposite really.

I am not sure this complies with KYC laws.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#80

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Is it the same for small and medium sized company though? We spend quite a lot on infosec with the premise that a breach could put us out of business since we can't afford to tarnish our reputation and loose key clients. Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and b…

> they fall into the (unfortunately) too big to fail category

They're absolutely not too big to fail. Equifax or FB? Other than the unfortunate employees and their families, does anyone give a shit? No. No one suffers. To the contrary, thinning sick herd members helpfully invigorates the health of the surviving individuals.

What these organization are are in too many pockets to be too big to jail. It's a trope but it's a fact, Jack

Edits for herd reference and reduced snark

Post reply on HN