An unnamed large bank in the US uses "admin"/"changeme" for a customer database. I'd love to say more about it but unfortunately that would probably identify me/them.
Equifax securities fraud class action [pdf]
131–140 of 227 posts
Re: Equifax securities fraud class action [pdf]
#132These security nightmares begs the question: Why don't databases use asymmetric keys and authenticate & authorize access? Why are we still reliant on password based authentication? If it's simply the question of key management and distribution, that's a solved problem.
Re: Equifax securities fraud class action [pdf]
#133An unnamed large bank in the US uses "admin"/"changeme" for a customer database. I'd love to say more about it but unfortunately that would probably identify me/them.
Will you change it?
Re: Equifax securities fraud class action [pdf]
#134This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…
Unfortunately if there were such audits, I can practically guarantee that it would end up being bottom-dollar devs employed through unions or insider dealings. And the larger companies like equifax would likely have a deal allowing them to self audit to some extent. See: Boeing, iso certifications, building inspectors, health inspectors, any large civil engineering or aero firm, etc. To be clear, I do agree that it i…
Re: Equifax securities fraud class action [pdf]
#135Re: Equifax securities fraud class action [pdf]
#136Earlier quoted context omitted.
Here's the Amended Complaint: https://www.courtlistener.com/recap/gov.uscourts.gand.241666...
So bullet point # 225 from that complaint basically says the same as the PDF we're discussing: >Likewise, Equifax “protected” one of its portals used to manage credit disputes with the username ‘admin’ and password ‘admin.’ This portal allowed access to a vast cache of personal information, including employee names, emails, usernames, passwords, consumer complaint records, and the Argentinian equivalent of Social Sec…
Re: Equifax securities fraud class action [pdf]
#137Re: Equifax securities fraud class action [pdf]
#138This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…
Re: Equifax securities fraud class action [pdf]
#139> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…
Re: Equifax securities fraud class action [pdf]
#140The password for that console was sesame. Transactions were testworded but otherwise sent in plain text. When I worked in Europe a few years later I constructed by own telex bankwire transaction from a hotel in Italy. It was to my account for my money but it worked, no questions asked.