Earlier quoted context omitted.
Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?
That is hilariously backwards. "Social Conservatives" have done plenty to try an protect or aid constituents, but it's held up by the Grand Old Party in the Senate.
Capital One’s breach was inevitable, because we did nothing after Equifax
101–110 of 161 posts
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#102In my opinion organizations still don't rely enough on "defense in depth" techniques to protect sensitive data. Breaching the WAF and gaining access to S3 files shouldn't suffice to gain access to the raw data. Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized. I couldn't find information about the exact use case of the data but as it was stored in S3 I w…
I find that in large organizations, business only cares about business. Maybe because they can't be bothered with IT or security or any of the geeky disciplines. I'm pretty sure it's all about soft skills: they just can't handle dealing with folks that lack soft skills and those geeky, nerdy folks running the technology stack lack soft skills and only ever ask to spend money ... If you, tech geek, learn enough to spe…
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#103Earlier quoted context omitted.
I am pretty sure the vast majority of people don't even know about these breaches, and even if they do it's news that passes them by quickly. Maybe a rant or two on Facebook and then onto the next thing. Almost everyone will continue to use their Capital One credit card and the company will barely see a blip in their revenue.
When the news is mainly about people dying, someone selling stolen rolodexes sounds insignificant in comparison
100m people losing a minute of their life to handling this (lets call it nanodeath) is 190 continuous years of wasted time that you could have spent with your family, napping, reading or other pleasurable life things.
That’s the kind of math that, say, an insurer, should do to determine whether an intervention should be paid for.
But usually you just get called a monster for doing that kind of math.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#104This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…
To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#105There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…
Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?
Let's take freedom of speech. One side believes it's unlimited, and the other doesn't. How do you compromise on that? You can't. How do you solve that problem? You don't, it's not the government's job to solve all of society's problems. That's the point most people don't understand: quit trying to control the behavior of others.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#106Earlier quoted context omitted.
Well then easy solution: you refrain from opting in into personal ID cards, but you're responsible for all fraudular and other activity that is done under your name and could have been prevented by having an ID card lock down your identity.
Holding victims civilly liable for fraud is not a fair or liberal alternative to government monitoring. Should I also have no recourse when my house is burglarized if I fail to install cameras that send a feed to the police?
That comparison is wrong on multiple levels:
1) you may be automatically at fault already when not doing what the government is requiring you to do for public safety reasons (for example, your car has a rusty brake pipe, you do not do the yearly mandatory checkup, pipe explodes, car crashes into something)
2) contrary to a feed to the police, showing your federal ID card at a bank or car dealership when applying for a loan does not cause the government to know you were at the bank or the car dealership. Therefore it is not surveillance.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#107Earlier quoted context omitted.
It's actually a lot harder than you'd imagine to break into security considering how much outrage and demand there seems to be in the press and on forums. Maybe this WAF wasn't the greatest software though. Simply buying something and squeezing it into your tech stack isn't enough. You have to know how it works or it could be the thing that gives a foothold to an attacker.
I spend a considerable amount of time pentesting. I understand it very well
The talent pool is woefully underfilled.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#108This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…
After validating your ID, you can use the app to do 2FA with most major services in the country, including almost every bank and financial institution.
A program like this could go a long way in the US to help cut down on the issue you describe.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#109Earlier quoted context omitted.
Is it the same for small and medium sized company though? We spend quite a lot on infosec with the premise that a breach could put us out of business since we can't afford to tarnish our reputation and loose key clients. Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and b…
> they fall into the (unfortunately) too big to fail category They're absolutely not too big to fail. Equifax or FB? Other than the unfortunate employees and their families, does anyone give a shit? No. No one suffers. To the contrary, thinning sick herd members helpfully invigorates the health of the surviving individuals. What these organization are are in too many pockets to be too big to jail. It's a trope but it…
And yeah, ditto Equifax. There are two other credit agencies already. They're all same-ish as far as I can tell. Pretty sure there are only three so they can pretend there's competition, not for any actual purpose. Again, it might be an opening for a new competitor anyway, while causing minimal short-term harm.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#110This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…
To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?
* The PII wasn't stolen from me, it was negligently exposed by services I contract with (and pay!) and others that I have no formal relationship with (like Equifax).
* It wasn't defrauding me, it was defrauding services I contract with (and others) who failed to verify my identity.
And yet somehow I'm obligated to do the cleanup myself.