What guarantees does Amazon sell to AWS clients regarding the security of their data?
Capital One’s breach was inevitable, because we did nothing after Equifax
121–130 of 161 posts
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#122Earlier quoted context omitted.
I agree, SSN's are a poor form of authentication. What's missing from these conversations is realistic approaches to fixing it. It's a lot like healthcare: plenty of people want to get rid of Obamacare, but they fail to explain what will replace it. > For the public system, assign to every participant a true unique identifier, rather than the SSN which explicitly states should not be used as such. This will work for…
> This will work for a time, but what happens when the next breach occurs? The UUID shouldn't be assumed to be private information - authentication should be built around the assumption that this identifier is a public identifier - like a name, but guaranteed to be unique. > Physical authentication probably means fingerprints, face data, correct? These are already compromised. Worse yet, they cannot be changed. Even…
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#123Earlier quoted context omitted.
This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?
Problem is, executives don't understand those things. Of course it's very simple to point a finger at them, but they rarely are tech savvy, and they are there to run the company, not micromanage every decision every department makes.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#124There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…
Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?
Why is your assumption that the social conservatives are the ones that have to compromise? Shouldn't both sides be compromising?
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#125Earlier quoted context omitted.
The UK is a special case and will not be "Europe" for long besides. Homogenisation of rules can take a while, especially when there is a cultural aversion to them. In this case I'd say there simply has not been enough time for this to happen.
Ireland also does not have mandatory ID, nor do the Nordic countries. I don't think it's as clear cut as you make it out to be.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#126Earlier quoted context omitted.
To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?
Identity theft is an amazing PR term, not-so-subtly shifting blame onto the individual whose identity was fraudulently used. * The PII wasn't stolen from me, it was negligently exposed by services I contract with (and pay!) and others that I have no formal relationship with (like Equifax). * It wasn't defrauding me, it was defrauding services I contract with (and others) who failed to verify my identity. And yet some…
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#127Earlier quoted context omitted.
I agree, SSN's are a poor form of authentication. What's missing from these conversations is realistic approaches to fixing it. It's a lot like healthcare: plenty of people want to get rid of Obamacare, but they fail to explain what will replace it. > For the public system, assign to every participant a true unique identifier, rather than the SSN which explicitly states should not be used as such. This will work for…
> This will work for a time, but what happens when the next breach occurs? The UUID shouldn't be assumed to be private information - authentication should be built around the assumption that this identifier is a public identifier - like a name, but guaranteed to be unique. > Physical authentication probably means fingerprints, face data, correct? These are already compromised. Worse yet, they cannot be changed. Even…
In that case, we already have this today: At the state level, most citizens have a Drivers license or State ID, both of which have a unique ID. At the federal level, all US passports have a unique Passport Number. Granted, not all citizens have a passport, but that system is in place to grant citizens unique identifiers.
And yet we still have identity issues. So this is part of the solution.
> Even if those are compromised, that doesn't mean it has to be easy to impersonate you. The solution may be low-tech - you may have to physically present yourself to a human who assesses if you are indeed who you say you are before opening an account. The higher tech solution physical authentication might require something akin to chip-and-pin or a (revocable) token generator a la Ubikey
This is a great idea. I believe France's healthcare system requires every citizen to have a card [1], which uses a chip and pin tech to authenticate the person with their doctor. This could be used for online services or over the phone too.
What the US needs is a branch specifically for administring these "identity cards". The Social Security Administration could be rebranded to an "Identity Administration" or something, then they will manage the distribution and revocation / recycling of these national ID cards.
But for some reason Americans get spooked when you say the words "National ID". Something about how "socialism is bad" and all that.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#128There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…
I agree that we've been given clear signals that losing consumer data won't result in any negative repercussions for your business from government. Unfortunately none of us are customers of equifax - the companies we share our data with are. And those companies don't care, and include every bank. For Capital One, or other companies with which we directly do business, I think there's likely to be more direct ramificat…
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#129Earlier quoted context omitted.
Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?
> When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents? July 1st, 2019 H.R. 3151 "Taxpayer First Act This bill revises provisions relating to the Internal Revenue Service (IRS), its customer service, enforcement procedures, cybersecurity and identity protection, management of information technology, and use of electronic systems." http…
At least the 9/11 first responders bill was about allocating resources to do something, but the main reason it doesn’t serve your point is the fact it stood for 18 years as an example of our government’s incompetence and inability to do basic, non controversial things.
Re: Capital One’s breach was inevitable, because we did nothing after Equifax
#130This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…