Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

101–110 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#101
post #96
post #70

Earlier quoted context omitted.

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

That is hilariously backwards. "Social Conservatives" have done plenty to try an protect or aid constituents, but it's held up by the Grand Old Party in the Senate.

Social conservatives usually mean GOP when referring to American politics

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#102
post #63

In my opinion organizations still don't rely enough on "defense in depth" techniques to protect sensitive data. Breaching the WAF and gaining access to S3 files shouldn't suffice to gain access to the raw data. Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized. I couldn't find information about the exact use case of the data but as it was stored in S3 I w…

I find that in large organizations, business only cares about business. Maybe because they can't be bothered with IT or security or any of the geeky disciplines. I'm pretty sure it's all about soft skills: they just can't handle dealing with folks that lack soft skills and those geeky, nerdy folks running the technology stack lack soft skills and only ever ask to spend money ... If you, tech geek, learn enough to spe…

The small and medium companies that seem to be rethinking IT security are the ones hit by a cryptolocker.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#103
post #74

Earlier quoted context omitted.

I am pretty sure the vast majority of people don't even know about these breaches, and even if they do it's news that passes them by quickly. Maybe a rant or two on Facebook and then onto the next thing. Almost everyone will continue to use their Capital One credit card and the company will barely see a blip in their revenue.

When the news is mainly about people dying, someone selling stolen rolodexes sounds insignificant in comparison

It does to me.

100m people losing a minute of their life to handling this (lets call it nanodeath) is 190 continuous years of wasted time that you could have spent with your family, napping, reading or other pleasurable life things.

That’s the kind of math that, say, an insurer, should do to determine whether an intervention should be paid for.

But usually you just get called a monster for doing that kind of math.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#104
post #87

This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…

To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?

The concept of "identity theft" (i.e. the hacker stole your identity vs. the hacker used false credentials to steal from the bank) is probably the single greatest feat of social engineering of our times.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#105
post #70

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

Compromise implies both sides have something to give. One side doesn't have anything the other side wants, so there can be no compromise.

Let's take freedom of speech. One side believes it's unlimited, and the other doesn't. How do you compromise on that? You can't. How do you solve that problem? You don't, it's not the government's job to solve all of society's problems. That's the point most people don't understand: quit trying to control the behavior of others.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#106

Earlier quoted context omitted.

Well then easy solution: you refrain from opting in into personal ID cards, but you're responsible for all fraudular and other activity that is done under your name and could have been prevented by having an ID card lock down your identity.

Holding victims civilly liable for fraud is not a fair or liberal alternative to government monitoring. Should I also have no recourse when my house is burglarized if I fail to install cameras that send a feed to the police?

> Should I also have no recourse when my house is burglarized if I fail to install cameras that send a feed to the police?

That comparison is wrong on multiple levels:

1) you may be automatically at fault already when not doing what the government is requiring you to do for public safety reasons (for example, your car has a rusty brake pipe, you do not do the yearly mandatory checkup, pipe explodes, car crashes into something)

2) contrary to a feed to the police, showing your federal ID card at a bank or car dealership when applying for a loan does not cause the government to know you were at the bank or the car dealership. Therefore it is not surveillance.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#107
post #42

Earlier quoted context omitted.

It's actually a lot harder than you'd imagine to break into security considering how much outrage and demand there seems to be in the press and on forums. Maybe this WAF wasn't the greatest software though. Simply buying something and squeezing it into your tech stack isn't enough. You have to know how it works or it could be the thing that gives a foothold to an attacker.

I spend a considerable amount of time pentesting. I understand it very well

Not that. Break into it as a job.

The talent pool is woefully underfilled.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#108
post #87

This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…

The Belgians have this tool called "itsme" which acts as authentication manager/digital signature tool with authorized partners.

After validating your ID, you can use the app to do 2FA with most major services in the country, including almost every bank and financial institution.

https://www.itsme.be/en/

A program like this could go a long way in the US to help cut down on the issue you describe.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#109

Earlier quoted context omitted.

Is it the same for small and medium sized company though? We spend quite a lot on infosec with the premise that a breach could put us out of business since we can't afford to tarnish our reputation and loose key clients. Though I kind of agree that with Equifax and Facebook there weren't much consequences, to me they fall into the (unfortunately) too big to fail category, ie. most of Facebook members don't care and b…

> they fall into the (unfortunately) too big to fail category They're absolutely not too big to fail. Equifax or FB? Other than the unfortunate employees and their families, does anyone give a shit? No. No one suffers. To the contrary, thinning sick herd members helpfully invigorates the health of the surviving individuals. What these organization are are in too many pockets to be too big to jail. It's a trope but it…

The failure of Facebook might well be stimulative to employment and the economy. Imagine the wave of startups and new initiatives from other companies trying to compete in all the areas Facebook's in now. And unlike banks no significant part of the broader economy is at risk if facebook.com and instagram.com start 404ing forever tomorrow. A hiccup in the "influencer" economy, such as it is, which is negligible anyway, and they'll all have new homes one place or another (or several) inside a week and be building their followings back up.

And yeah, ditto Equifax. There are two other credit agencies already. They're all same-ish as far as I can tell. Pretty sure there are only three so they can pretend there's competition, not for any actual purpose. Again, it might be an opening for a new competitor anyway, while causing minimal short-term harm.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#110
post #87

This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…

To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?

Identity theft is an amazing PR term, not-so-subtly shifting blame onto the individual whose identity was fraudulently used.

* The PII wasn't stolen from me, it was negligently exposed by services I contract with (and pay!) and others that I have no formal relationship with (like Equifax).

* It wasn't defrauding me, it was defrauding services I contract with (and others) who failed to verify my identity.

And yet somehow I'm obligated to do the cleanup myself.

Post reply on HN