Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

101–110 of 227 posts

Re: Equifax securities fraud class action [pdf]

#101
This might seem shocking, but I did internals for many years and the number of networks I completely compromised via SQL Server is pretty funny. Almost all of them. sa/(blank) -- run xp_cmdshell, abuse server privileges to pivot to other servers or right to domain admin, then compromise their non windows environment with all the access. Networks still get owned this way on internals / red teams all the time. Granted we expect a company with all our personal data to do better, but they are still just a big company making the same terrible choices as everyone else :)

Re: Equifax securities fraud class action [pdf]

#102

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

[deleted]

Re: Equifax securities fraud class action [pdf]

#103

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

Yup. According to formal logic, the answer then is just yes.

p or true => true

Re: Equifax securities fraud class action [pdf]

#104

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

It's quite possible that these were scheduled trades that were arranged far in advance before either executive was aware of the breach. So, no, not necessarily insider trading. The optics sure look bad, but it could just be shitty timing.

Re: Equifax securities fraud class action [pdf]

#105

Earlier quoted context omitted.

This was my thought. Why do we need three credit reporting agencies? TransUnion and Experian should be enough. I go through my reports and all three are pretty much the same.

As tempting as it is to thirst for blood in this case, what do you really want to go after is upper management. Credit rating isn't exactly a free market, but I'm very skeptical that we should reduce any significant oligopoly from three corporations to two.

My comment is only part blood thirst and part just wanting to simplify my credit report tracking from a consumer perspective. I would also like as few companies as possible having my personal information as possible especially after problems like this.

The other part is if I'm applying for any kind of credit, I assume the most conservative lender would look at all three results and just go with the lowest credit score.

But I agree, even in a semi free market, competition is good.

Re: Equifax securities fraud class action [pdf]

#106

Earlier quoted context omitted.

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

It's quite possible that these were scheduled trades that were arranged far in advance before either executive was aware of the breach. So, no, not necessarily insider trading. The optics sure look bad, but it could just be shitty timing.

Doesn't it say in the quote that these were not scheduled? !

Re: Equifax securities fraud class action [pdf]

#107

Earlier quoted context omitted.

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

It's quite possible that these were scheduled trades that were arranged far in advance before either executive was aware of the breach. So, no, not necessarily insider trading. The optics sure look bad, but it could just be shitty timing.

From the parent:

> These sales were not made pursuant to a Rule 10b5–1 trading plan.

Re: Equifax securities fraud class action [pdf]

#108

Earlier quoted context omitted.

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

It's quite possible that these were scheduled trades that were arranged far in advance before either executive was aware of the breach. So, no, not necessarily insider trading. The optics sure look bad, but it could just be shitty timing.

Given the above quote referencing https://www.investopedia.com/terms/r/rule-10b5-1.asp that seems unlikely.

Re: Equifax securities fraud class action [pdf]

#109

Earlier quoted context omitted.

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

It's quite possible that these were scheduled trades that were arranged far in advance before either executive was aware of the breach. So, no, not necessarily insider trading. The optics sure look bad, but it could just be shitty timing.

Is there another way they could have executed trades legally, without following rule 10b5-1?

https://www.investopedia.com/terms/r/rule-10b5-1.asp

Re: Equifax securities fraud class action [pdf]

#110
post #55
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

The laws already exist, the penalty is just too small. With higher penalties there would be an insurance market where the insurers set standards and performs audits. Standards set by buerocrats are usually written by special interest groups and don't achieve the desired outcome at a good cost.

It's a recent trend that public corporations are being punished through securities fraud lawsuits since conventional regulators have been bought out.

Just about any managerial incompetence can be spun as "securities fraud" since the basic presumption of most companies is that management is competent. Maybe they'll give up on that in order to reduce their exposure to lawsuits.

Post reply on HN