I wonder if these companies are like one of the places i work at and have checkbox cybersecurity as opposed to real cybersecurity.......if you have ever had to ask your cybersecurity department "you really want me to loosen the permissions on those files so it will pass the scan¿", then you know what checkbox security is.......
Capital One’s breach was inevitable, because we did nothing after Equifax
81–90 of 161 posts
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#82It's so funny that with all these breaches, Equifax is the winner and gets 150M customers. Same thing happened with Desjardins (Quebec bank) recently.
They should've been forced to cover another company's credit monitoring solution, preferably a direct competitor's.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#83I soundly believe that in most of these cases some line level security person told middle management there might be an issue, but it wasn't dealt with because of time/money considerations ("Just Ship It") or there are many legacy things that never received a proper audit/fix schedule because of lack of people/experts to even see the issue.
One time financial penalties won't fix that, because I'd bet it might be cheaper to pay it. Criminally penalizing executives may not fix it, because some of these decisions likely never made their desk.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#84What guarantees does Amazon sell to AWS clients regarding the security of their data?
They make no promises about your side.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#85What guarantees does Amazon sell to AWS clients regarding the security of their data?
You got hacked? You must have configured it wrong because we already told you it was unhackable; Good luck proving it was our fault not yours.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#86There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…
For Capital One, or other companies with which we directly do business, I think there's likely to be more direct ramifications - namely people refusing to do business with them. Letting anyone access your customers' data is a good way to lose those customers.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#87Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that.
The solution is not better security with credit companies. The solution is some form of actual authentication. Preferably done by an organization dedicated to that (public would be best, private could work); not outsourced to organizations that are mostly geared towards determining credit worthiness.
For the public system, assign to every participant a true unique identifier, rather than the SSN which explicitly states should not be used as such.
For those citizens that do not want to register in this way, allow for physical authentication at physical locations.
In Europe this is far less of an issue since our population registration is a lot more comprehensive.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#88What guarantees does Amazon sell to AWS clients regarding the security of their data?
Lots! Tons and Tons and Tons! S3 is super secure and CAN NOT be hacked when properly configured and used according to our standard! You got hacked? You must have configured it wrong because we already told you it was unhackable; Good luck proving it was our fault not yours.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#89In my opinion organizations still don't rely enough on "defense in depth" techniques to protect sensitive data. Breaching the WAF and gaining access to S3 files shouldn't suffice to gain access to the raw data. Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized. I couldn't find information about the exact use case of the data but as it was stored in S3 I w…
I find that in large organizations, business only cares about business. Maybe because they can't be bothered with IT or security or any of the geeky disciplines. I'm pretty sure it's all about soft skills: they just can't handle dealing with folks that lack soft skills and those geeky, nerdy folks running the technology stack lack soft skills and only ever ask to spend money ... If you, tech geek, learn enough to spe…
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#90This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…