Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

131–140 of 227 posts

Re: Equifax securities fraud class action [pdf]

#132

These security nightmares begs the question: Why don't databases use asymmetric keys and authenticate & authorize access? Why are we still reliant on password based authentication? If it's simply the question of key management and distribution, that's a solved problem.

CockroachDB basically requires you to use mTLS to authenticate. It's fantastic.

Re: Equifax securities fraud class action [pdf]

#133
post #131
post #112

An unnamed large bank in the US uses "admin"/"changeme" for a customer database. I'd love to say more about it but unfortunately that would probably identify me/them.

Will you change it?

I petitioned those with the power to do so, but it fell on deaf ears. Unfortunately I did not have the authority to change it myself.

Re: Equifax securities fraud class action [pdf]

#134
post #120
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Unfortunately if there were such audits, I can practically guarantee that it would end up being bottom-dollar devs employed through unions or insider dealings. And the larger companies like equifax would likely have a deal allowing them to self audit to some extent. See: Boeing, iso certifications, building inspectors, health inspectors, any large civil engineering or aero firm, etc. To be clear, I do agree that it i…

Not accusing you of this, strictly speaking, but I see this as just more of the "if you regulate, they'll just do X, so don't bother" defeatism that is used all the time to argue against regulation, taxation, or any sort of policing of the rich and powerful. We have numerous examples of regulations actually working as designed. Notable failures (e.g. the IRS, the financial industry in the 2000s) are due in large part to persistent under-funding by Congress, rather than any inherent impossibility.

Re: Equifax securities fraud class action [pdf]

#136

Earlier quoted context omitted.

Here's the Amended Complaint: https://www.courtlistener.com/recap/gov.uscourts.gand.241666...

So bullet point # 225 from that complaint basically says the same as the PDF we're discussing: >Likewise, Equifax “protected” one of its portals used to manage credit disputes with the username ‘admin’ and password ‘admin.’ This portal allowed access to a vast cache of personal information, including employee names, emails, usernames, passwords, consumer complaint records, and the Argentinian equivalent of Social Sec…

But the complaint is similar. It's simply the allegations of one side. Part of the job of a trial is deciding the truth or falsity of these factual claims.

Re: Equifax securities fraud class action [pdf]

#138
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

I think it would be more efficient to give literally any teeth at all to prosecutors in these cases. Make it a big enough liability that they have to care. Let them figure out how to avoid the crippling fines.

Re: Equifax securities fraud class action [pdf]

#139

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

I'm confused why they didn't get prosecuted (at least not yet). The CIO actually got fined and sent to prison for insider trading: https://www.justice.gov/usao-ndga/pr/former-equifax-employee...

Re: Equifax securities fraud class action [pdf]

#140
When I worked for BofA decades ago, there was a PDP-11 at the center of a point to point network of other machines for handling SWIFT, Telex, FedWire .... This network turned over the assets of the bank every 4 days and BofA at the time was the largest private bank in the world.

The password for that console was sesame. Transactions were testworded but otherwise sent in plain text. When I worked in Europe a few years later I constructed by own telex bankwire transaction from a hotel in Italy. It was to my account for my money but it worked, no questions asked.

Post reply on HN