Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

11–20 of 227 posts

Re: Equifax securities fraud class action [pdf]

#11

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

Pressure from the higher ups to release to production can force you to dump all the IT security knowledge you accumulated over the years.

Re: Equifax securities fraud class action [pdf]

#14
post #3

Where does it say they used the defaults for their "main database"? As far as I'm aware it was "only" the password for a management portal for customer complaints, not the keys to the kingdom.

Yeah, that's true " a portal used to manage credit disputes"

Re: Equifax securities fraud class action [pdf]

#15

How is that possible with all the regulation?

Regulation doesn't matter directly. What matters is organisational culture. Regulation is one tool to change the culture of organisations in an industry, but it only works if it is

* Communicated clearly so that there is a path to compliance[1].

* Enforced with penalties so that people within non-infinite-budget organisations can sell[2] the change as a means to cut costs[3].

------

[1] If you only do the 1st, then it is like forcing children to swim by throwing them off a boat. Some people think that "sink or swim" forces someone to swim; it doesn't. It just presents two possibilities: swim or die.

[2] https://www.kalzumeus.com/2014/04/09/what-heartbleed-can-tea...

[3] https://www.kalzumeus.com/2011/10/28/dont-call-yourself-a-pr...

Re: Equifax securities fraud class action [pdf]

#16
>Equifax also failed to encrypt sensitive data in its custody. According to the Amended Complaint, Equifax admitted that sensitive personal information relating to hundreds of millions of Americans was not encrypted, but instead was stored in plaintext, making it easy for unauthorized users to read and misuse. Not only was this information unencrypted, but it also was accessible through a public-facing, widely used website.

Re: Equifax securities fraud class action [pdf]

#18
post #8

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will get through that in the first place."

Re: Equifax securities fraud class action [pdf]

#19

How is that possible with all the regulation?

I work with financial software and you'd be surprised how much of all this "regulation" is based on self assessments. Auditors are looking for liability shifts, not real security.

And auditors don't really have access to passwords etc. They can run an assessment tool to see that there's an account named "admin," but typically don't get access to /etc/shadow or passwords within applications.

Now a pentester? If they don't spot this during an assessment, they suck. But pentesting isn't always performed on a rigorous schedule.

Re: Equifax securities fraud class action [pdf]

#20
>For example, Equifax relied upon four digit pins derived from Social Security numbers and birthdays to guard personal information, despite the fact that these weak passwords had already been compromised in previous breaches. Furthermore, Equifax employed the username “admin” and the password “admin” to protect a portal used to manage credit disputes, a password that “is a surefire way to get hacked.” This portal contained a vast trove of personal information.
Post reply on HN