Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

81–90 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#81
I have been part of 12 data breaches, that i have been informed about, in the last 5ish years. I read about it and then move on at this point. I have a sick feeling credit monitoring with insurance is going to become the norm, just like house and car insurance. I am not sure why progressive and state farm dont have it yet on your policy (maybe they do).

I wonder if these companies are like one of the places i work at and have checkbox cybersecurity as opposed to real cybersecurity.......if you have ever had to ask your cybersecurity department "you really want me to loosen the permissions on those files so it will pass the scan¿", then you know what checkbox security is.......

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#82
post #21

It's so funny that with all these breaches, Equifax is the winner and gets 150M customers. Same thing happened with Desjardins (Quebec bank) recently.

The really bonkers part about the Equifax settlement is they're being permitted to "pay" the fine by giving away their own credit monitoring solution. They value at it as something like $15/month, but it likely costs them pennies to run. A good portion of those users will probably convert to paid users at the end of things - I strongly suspect they'll wind up profiting overall.

They should've been forced to cover another company's credit monitoring solution, preferably a direct competitor's.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#83
What exactly can "we" do other than the government creating some financial penalty for this?

I soundly believe that in most of these cases some line level security person told middle management there might be an issue, but it wasn't dealt with because of time/money considerations ("Just Ship It") or there are many legacy things that never received a proper audit/fix schedule because of lack of people/experts to even see the issue.

One time financial penalties won't fix that, because I'd bet it might be cheaper to pay it. Criminally penalizing executives may not fix it, because some of these decisions likely never made their desk.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#85
post #50

What guarantees does Amazon sell to AWS clients regarding the security of their data?

Lots! Tons and Tons and Tons! S3 is super secure and CAN NOT be hacked when properly configured and used according to our standard!

You got hacked? You must have configured it wrong because we already told you it was unhackable; Good luck proving it was our fault not yours.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#86

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

I agree that we've been given clear signals that losing consumer data won't result in any negative repercussions for your business from government. Unfortunately none of us are customers of equifax - the companies we share our data with are. And those companies don't care, and include every bank.

For Capital One, or other companies with which we directly do business, I think there's likely to be more direct ramifications - namely people refusing to do business with them. Letting anyone access your customers' data is a good way to lose those customers.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#87
This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'.

Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that.

The solution is not better security with credit companies. The solution is some form of actual authentication. Preferably done by an organization dedicated to that (public would be best, private could work); not outsourced to organizations that are mostly geared towards determining credit worthiness.

For the public system, assign to every participant a true unique identifier, rather than the SSN which explicitly states should not be used as such.

For those citizens that do not want to register in this way, allow for physical authentication at physical locations.

In Europe this is far less of an issue since our population registration is a lot more comprehensive.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#88
post #50

What guarantees does Amazon sell to AWS clients regarding the security of their data?

Lots! Tons and Tons and Tons! S3 is super secure and CAN NOT be hacked when properly configured and used according to our standard! You got hacked? You must have configured it wrong because we already told you it was unhackable; Good luck proving it was our fault not yours.

Can you actually substantiate a S3 security problem that wasn't user error? Because I've yet to hear of one.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#89
post #63

In my opinion organizations still don't rely enough on "defense in depth" techniques to protect sensitive data. Breaching the WAF and gaining access to S3 files shouldn't suffice to gain access to the raw data. Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized. I couldn't find information about the exact use case of the data but as it was stored in S3 I w…

I find that in large organizations, business only cares about business. Maybe because they can't be bothered with IT or security or any of the geeky disciplines. I'm pretty sure it's all about soft skills: they just can't handle dealing with folks that lack soft skills and those geeky, nerdy folks running the technology stack lack soft skills and only ever ask to spend money ... If you, tech geek, learn enough to spe…

Ridiculously accurate assessment of the situation. Incentives matter.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#90
post #87

This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…

To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?
Post reply on HN