Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

21–30 of 227 posts

Re: Equifax securities fraud class action [pdf]

#22

How is that possible with all the regulation?

I work with financial software and you'd be surprised how much of all this "regulation" is based on self assessments. Auditors are looking for liability shifts, not real security.

I was dumbfounded by this when I was consulting prior and worked with some banks on mortgage compliance. Almost everything about banking is self assessments and reporting. It is similar to the idea of Boeing doing self testing for the FAA and reporting all is fine. Regulation doesn't bring safety or security, it brings reporting that rarely gets analyzed and even if it is there is no way it will show anything but the most blatant of fraud etc. It is akin to closing the barn doors after the horses have all left, at least the banks can say hey 10 horses left, but nothing was done to prevent it and they won't get in trouble cause they reported on it.

At least that was kinda my takeaway from those jobs. I could just have a skewed version based on the stuff I worked on.

Re: Equifax securities fraud class action [pdf]

#23
post #8

Earlier quoted context omitted.

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will…

Colleague #4-20: Build various integrations to database, all with their own ways of storing credentials.

Colleague #2: "It's really past due time to change the database password, but first we have to make sure all critical systems can still access the database."

Re: Equifax securities fraud class action [pdf]

#25
I'm using that headline as our thought of the day in group chat at work. Because that is just egregious and negligent.

Nobody thought to raise that? to anyone?

Although I can understand. I have several people who now call themselves DevOps on a project who have practically zero experience with systems operations _or_ development, and have done some utterly incomprehensibly stupid things. It doesn't matter how fancy your cloud tech is, if someone creates VPCs with default ALLOW ALL rules, stuff is going to get compromised. Worse yet, some are _fighting_ against changing the ingress rules because that would show that they were wrong! I'd at the very least rotate them out and replace them if I could. (rant over)

Re: Equifax securities fraud class action [pdf]

#28

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

Usually they rely on some other mechanism for security. Like you can only access the portal admin page from the intranet or a few IP addresses. That has failed, not the fact that they didn't change the password.

Re: Equifax securities fraud class action [pdf]

#29

I'm using that headline as our thought of the day in group chat at work. Because that is just egregious and negligent. Nobody thought to raise that? to anyone? Although I can understand. I have several people who now call themselves DevOps on a project who have practically zero experience with systems operations _or_ development, and have done some utterly incomprehensibly stupid things. It doesn't matter how fancy y…

It happens quite a lot - nowadays services are deployed into the cloud where people are more security concious but when people deploy on-prem they are often more negligent

Re: Equifax securities fraud class action [pdf]

#30
post #8

Earlier quoted context omitted.

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will…

Excellent use of copy paste from another thread. Upvote!
Post reply on HN