Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

71–80 of 227 posts

Re: Equifax securities fraud class action [pdf]

#71

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

Security is a cost and nuisance. It's the first thing to be cut. To keep high security at all times you need: 1) Process aka bureaucracy. Mandatory checklists. Checklists are returned and inspected by others. Anything missing or uncertain is checked again and fixed. 2) People who are responsible for security are independent from other concerns. They can have adversarial relationship with people responsible for gettin…

I'd love to see a list of organisations at which these practices are the norm.

Dealing with standard practices, most especially violations of your #2, have contributed in large part to my getting off this ride.

Re: Equifax securities fraud class action [pdf]

#72

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

It sounds like you aren't lazy and negligent -- not everyone is like you, unfortunately.

Re: Equifax securities fraud class action [pdf]

#73
post #52

Earlier quoted context omitted.

Right. We do this with accounting firms, and I think we should do it with data security as well. Does it cost money? Sure. But that's the cost of doing business. If you have personal info like this and you profit from it, then you are also responsible for safeguarding it.

In being careful to not build an impossible barrier-to-entry, perhaps the requirement becomes active upon certain criteria (e.g. number of users)

There's already an impossible barrier to entry. The ones that already exist have data on almost every person in the US, and your new upstart doesn't.

Re: Equifax securities fraud class action [pdf]

#74
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Yes. You can't rely on capitalism to regulate businesses, much less to regulate businesses who deal with the private information of people other than their customers. (See also: Google, Facebook)

Re: Equifax securities fraud class action [pdf]

#75

Why is Equifax still a thing?

This was my thought. Why do we need three credit reporting agencies? TransUnion and Experian should be enough. I go through my reports and all three are pretty much the same.

Ideally, competition would be good.

Though competition without consequences clearly isn't.

I'd like to see a few more bureaux. Or the role nationalised. Government is at least in theory answerable to the citizens. Though government as financial vetter introduces numerous other issues.

The question of why people require credit for day-to-day financial activities, many carrying balances, is another part of this question. Sufficient pay, collective bargaining, workplace and tenant / homeowner protections, and wealth and land taxes are a few policy changes outside the data security arena which would help markedly.

Re: Equifax securities fraud class action [pdf]

#76
post #59
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

i think it's 123456 because users get confused on the phone. - What's the password - password - Yes, the password!

"What's the frequency, Kenneth?" https://en.wikipedia.org/wiki/What%27s_the_Frequency,_Kennet...

Re: Equifax securities fraud class action [pdf]

#77
post #47

Earlier quoted context omitted.

Are you being serious? If a bank "locked" its vault by tying the door closed with yarn, would you say "at least they locked it"?

I believe it's a joke referencing the default password for mssql for many years of sa/null. Eventually the install started forcing the user to change it to something, but for a time there were many mssql databases out there with a default password of null.

Oracles default password is change_on_install and you would be surprised at how many DBAs type it every day without reading it...

Re: Equifax securities fraud class action [pdf]

#78

Earlier quoted context omitted.

Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will…

Colleague #4-20: Build various integrations to database, all with their own ways of storing credentials. Colleague #2: "It's really past due time to change the database password, but first we have to make sure all critical systems can still access the database."

Which is why forward planning and prompt action is worth so much.

I know I'm stating the obvious, but I've seen some worrying attitudes of "just in time" that seem to go hand in hand with a misunderstanding of Scrum Sprints or Kanban. Where people concentrate on the tree and ignore the vast interconnected forest around them.

Re: Equifax securities fraud class action [pdf]

#79
post #59

Earlier quoted context omitted.

i think it's 123456 because users get confused on the phone. - What's the password - password - Yes, the password!

"What's the frequency, Kenneth?" https://en.wikipedia.org/wiki/What%27s_the_Frequency,_Kennet...

Alternative reference is Spaceballs: Dark Helmet's locker combination.
Post reply on HN