Equifax securities fraud class action [pdf]
21–30 of 227 posts
Re: Equifax securities fraud class action [pdf]
#22How is that possible with all the regulation?
I work with financial software and you'd be surprised how much of all this "regulation" is based on self assessments. Auditors are looking for liability shifts, not real security.
At least that was kinda my takeaway from those jobs. I could just have a skewed version based on the stuff I worked on.
Re: Equifax securities fraud class action [pdf]
#23Earlier quoted context omitted.
I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".
Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will…
Colleague #2: "It's really past due time to change the database password, but first we have to make sure all critical systems can still access the database."
Re: Equifax securities fraud class action [pdf]
#24Re: Equifax securities fraud class action [pdf]
#25Nobody thought to raise that? to anyone?
Although I can understand. I have several people who now call themselves DevOps on a project who have practically zero experience with systems operations _or_ development, and have done some utterly incomprehensibly stupid things. It doesn't matter how fancy your cloud tech is, if someone creates VPCs with default ALLOW ALL rules, stuff is going to get compromised. Worse yet, some are _fighting_ against changing the ingress rules because that would show that they were wrong! I'd at the very least rotate them out and replace them if I could. (rant over)
Re: Equifax securities fraud class action [pdf]
#26At least they had a password /s
Re: Equifax securities fraud class action [pdf]
#27Re: Equifax securities fraud class action [pdf]
#28I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).
Re: Equifax securities fraud class action [pdf]
#29I'm using that headline as our thought of the day in group chat at work. Because that is just egregious and negligent. Nobody thought to raise that? to anyone? Although I can understand. I have several people who now call themselves DevOps on a project who have practically zero experience with systems operations _or_ development, and have done some utterly incomprehensibly stupid things. It doesn't matter how fancy y…
Re: Equifax securities fraud class action [pdf]
#30Earlier quoted context omitted.
I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".
Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will…