Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

121–130 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#121
post #50

What guarantees does Amazon sell to AWS clients regarding the security of their data?

A lot, they probably set the bucket as world-readable with no encryption, which AWS warns you about, their engineer just ignored the warning

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#122

Earlier quoted context omitted.

I agree, SSN's are a poor form of authentication. What's missing from these conversations is realistic approaches to fixing it. It's a lot like healthcare: plenty of people want to get rid of Obamacare, but they fail to explain what will replace it. > For the public system, assign to every participant a true unique identifier, rather than the SSN which explicitly states should not be used as such. This will work for…

> This will work for a time, but what happens when the next breach occurs? The UUID shouldn't be assumed to be private information - authentication should be built around the assumption that this identifier is a public identifier - like a name, but guaranteed to be unique. > Physical authentication probably means fingerprints, face data, correct? These are already compromised. Worse yet, they cannot be changed. Even…

Careful what you wish for with the low-tech solution. One of the most effective vectors for phone number port-out scams is just showing up to a local cell phone shop and presenting a fake id. Often this is completely free for the attacker since they can just opt to have a new phone added to the account on credit too.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#123

Earlier quoted context omitted.

This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?

Problem is, executives don't understand those things. Of course it's very simple to point a finger at them, but they rarely are tech savvy, and they are there to run the company, not micromanage every decision every department makes.

Hiring people that don't know what they're doing isn't a reasonable excuse, such as Susan Mauldin, the ex-CSO of Equifax with a bachelor in music and no technical or security related education/training

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#124
post #70

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else.

Why is your assumption that the social conservatives are the ones that have to compromise? Shouldn't both sides be compromising?

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#125
post #15

Earlier quoted context omitted.

The UK is a special case and will not be "Europe" for long besides. Homogenisation of rules can take a while, especially when there is a cultural aversion to them. In this case I'd say there simply has not been enough time for this to happen.

Ireland also does not have mandatory ID, nor do the Nordic countries. I don't think it's as clear cut as you make it out to be.

The Irish (PSC) Public Services Card is getting close to being a de facto ID card at this point.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#126
post #110

Earlier quoted context omitted.

To this point: does “identity theft” really exist, or is this simply a reframing of banks, etc., completely failing at authentication?

Identity theft is an amazing PR term, not-so-subtly shifting blame onto the individual whose identity was fraudulently used. * The PII wasn't stolen from me, it was negligently exposed by services I contract with (and pay!) and others that I have no formal relationship with (like Equifax). * It wasn't defrauding me, it was defrauding services I contract with (and others) who failed to verify my identity. And yet some…

Yup. The quickest way to stop these sorts of things from happening is to make the banks responsible for accepting/using stolen information(ie facilitating identify theft). For some odd reason, its the person's responsibility now that the bank used fraudulent information.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#127

Earlier quoted context omitted.

I agree, SSN's are a poor form of authentication. What's missing from these conversations is realistic approaches to fixing it. It's a lot like healthcare: plenty of people want to get rid of Obamacare, but they fail to explain what will replace it. > For the public system, assign to every participant a true unique identifier, rather than the SSN which explicitly states should not be used as such. This will work for…

> This will work for a time, but what happens when the next breach occurs? The UUID shouldn't be assumed to be private information - authentication should be built around the assumption that this identifier is a public identifier - like a name, but guaranteed to be unique. > Physical authentication probably means fingerprints, face data, correct? These are already compromised. Worse yet, they cannot be changed. Even…

> The UUID shouldn't be assumed to be private information - authentication should be built around the assumption that this identifier is a public identifier - like a name, but guaranteed to be unique.

In that case, we already have this today: At the state level, most citizens have a Drivers license or State ID, both of which have a unique ID. At the federal level, all US passports have a unique Passport Number. Granted, not all citizens have a passport, but that system is in place to grant citizens unique identifiers.

And yet we still have identity issues. So this is part of the solution.

> Even if those are compromised, that doesn't mean it has to be easy to impersonate you. The solution may be low-tech - you may have to physically present yourself to a human who assesses if you are indeed who you say you are before opening an account. The higher tech solution physical authentication might require something akin to chip-and-pin or a (revocable) token generator a la Ubikey

This is a great idea. I believe France's healthcare system requires every citizen to have a card [1], which uses a chip and pin tech to authenticate the person with their doctor. This could be used for online services or over the phone too.

What the US needs is a branch specifically for administring these "identity cards". The Social Security Administration could be rebranded to an "Identity Administration" or something, then they will manage the distribution and revocation / recycling of these national ID cards.

But for some reason Americans get spooked when you say the words "National ID". Something about how "socialism is bad" and all that.

[1]: https://en.wikipedia.org/wiki/Carte_Vitale

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#128

There is no reason to spend one dime on infosec after the big Equifax breach and the numerous Facebook hacks/intentional spreading of data. They already lost all the most important data for every American and both companies are doing far better than ever. Nobody went to jail, everyone gets to keep making money. You should worry about lightning strikes and like solar flares disrupting your business before you worry ab…

I agree that we've been given clear signals that losing consumer data won't result in any negative repercussions for your business from government. Unfortunately none of us are customers of equifax - the companies we share our data with are. And those companies don't care, and include every bank. For Capital One, or other companies with which we directly do business, I think there's likely to be more direct ramificat…

Wells Fargo did much worse with actually defrauding their customers, ruining some lives, and only got a slap on the wrist.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#129
post #98
post #70

Earlier quoted context omitted.

Part of this problem is that Congress has simply stopped functioning for the past ten years or so. They're pretty much just keeping the lights on while social conservatives refuse to compromise with anyone else. When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents?

> When's the last time you remember high-profile federal legislation being passed with the intention of protecting or aiding constituents? July 1st, 2019 H.R. 3151 "Taxpayer First Act This bill revises provisions relating to the Internal Revenue Service (IRS), its customer service, enforcement procedures, cybersecurity and identity protection, management of information technology, and use of electronic systems." http…

What makes you say this bill is doing more than call for a minimalist response to tax return fraud (giving people “identity protection ID number” to use with ID theft cases and a single phone number to call about tax related identity theft) and make updates correcting obvious flaws in the tax code (aka keeping the lights on)? The provisions in this law will not make it less likely that someone will file a tax return with your stolen info, and not make it easier to get it made right if that does happen.

At least the 9/11 first responders bill was about allocating resources to do something, but the main reason it doesn’t serve your point is the fact it stood for 18 years as an example of our government’s incompetence and inability to do basic, non controversial things.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#130
post #87

This is a bigger issue than 'credit agencies have poor security'. This is an issue of 'standard authentication in the US is negligently weak'. Knowledge of a SSN and other public information should never be enough to authenticate any person. That means no credit issued based on that, no tax returns filed or viewed based on that, no checks sent based on that. The solution is not better security with credit companies.…

I really wish the mainstream media could pick up more on this, and instead of framing all these breaches and news as Identity Theft, reframe them to the credit companies offloading burden of risk onto consumers. Most people don't even have the context of what is really going on with this. we all should really assume that our SSN & PII is splattered across hundreds if not thousands of databases all in a various state of protection, and not be held liable for the lazy credit companies who's business is based on not making it hard to get instant credit for all those emotional purchases...
Post reply on HN