Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

91–100 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#91
post #87

This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…

To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?

Point. Identity hacking would be more accurate.

In that the attacker is creatively operating the system, rather than really possessing magic knowledge.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#93
post #15
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

The UK is a special case and will not be "Europe" for long besides. Homogenisation of rules can take a while, especially when there is a cultural aversion to them. In this case I'd say there simply has not been enough time for this to happen.

Ireland also does not have mandatory ID, nor do the Nordic countries. I don't think it's as clear cut as you make it out to be.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#94
> The Equifax incident should have sparked a fire under the credit giants.

I get what the author is trying to say, but based on the entire remainder of this article, the large credit firms are doing exactly the right thing (for their shareholders) by not spending tons of money on security.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#95
post #70

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

The Consumer Financial Protection Bureau just barely makes the mark. Of course, Trump started gutting it almost immediately after joining office.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#96
post #70

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

That is hilariously backwards. "Social Conservatives" have done plenty to try an protect or aid constituents, but it's held up by the Grand Old Party in the Senate.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#97

In my opinion organizations still don't rely enough on "defense in depth" techniques to protect sensitive data. Breaching the WAF and gaining access to S3 files shouldn't suffice to gain access to the raw data. Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized. I couldn't find information about the exact use case of the data but as it was stored in S3 I w…

> Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized.

Sorry, just to nitpick, creating anonymized data isn't that easy, and I'm worried something like that would get miss-used like some password breaches (the passwords were encrypted with md5, they're still secure). I can store all this customer data without consideration, because a company thinks they've anonymized something that isn't actually anonymized.

Here's a blog post I made on the topic: https://gravitational.com/blog/hashing-for-anonymization/

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#98
post #70

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

> When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

July 1st, 2019

H.R. 3151

"Taxpayer First Act

This bill revises provisions relating to the Internal Revenue Service (IRS), its customer service, enforcement procedures, cybersecurity and identity protection, management of information technology, and use of electronic systems."

https://www.congress.gov/bill/116th-congress/house-bill/3151...

Just because actual legislation is too boring for cable news and NPR doesn't mean it's not happening.

You can find all the bills that passed into law here: https://www.congress.gov/advanced-search/legislation?congres...

PS: Believe the 9/11 first responders bill would be more recent, but I figured people would take issue with that as a celebrity bill.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#99

Earlier quoted context omitted.

This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?

Problem is, executives don't understand those things. Of course it's very simple to point a finger at them, but they rarely are tech savvy, and they are there to run the company, not micromanage every decision every department makes.

Then they had better start hiring replacements soon..

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#100

Earlier quoted context omitted.

The consequence is I won't use them and as much as possible others won't either. It's not the same as no consequence, but I get what you mean. The government plays so nicely with business that we shouldn't expect even a day's worth of business profits in related fines.

I wish I had the option of not using Equifax (or Experian, or Transunion, or the secret telecom one), but apparently there is no way to opt out of all your most personal data being the product they sell in these private systems.

LexisNexis? there are a bunch of opaque databases that can contain your info
Post reply on HN