Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

141–150 of 227 posts

Re: Equifax securities fraud class action [pdf]

#141

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

[deleted]

Re: Equifax securities fraud class action [pdf]

#142
post #60
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

There could be whistleblower protections for hackers. Consider the previous attitude was hackers are causing millions of dollars of damage and need to be thrown in prison. With the proliferation of state sponsored and counter intelligence hacking over the past 15 years, no one believes you can make anything secure just by throwing enough teenage script kiddies in federal prison. The reverse now is companies are takin…

While nothing is impervious that really has nothing to do with Equifax. Equifax is a case of gross negligence and malfeasance. There were no less than three security audits of Equifax going back as early as 2014. Every audit indicated major security vulnerabilities and Smith disregarded these audits each time.

Re: Equifax securities fraud class action [pdf]

#144
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Yes. You can't rely on capitalism to regulate businesses, much less to regulate businesses who deal with the private information of people other than their customers. (See also: Google, Facebook)

And you can’t trust the government to regulate business either between the revolving door of government and private industry and each party is biased for and against certain industries.

Re: Equifax securities fraud class action [pdf]

#145

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

It's possible they were already planning to make those sales. Executives who can potentially have inside information often need to tell the SEC far ahead of time about sales they intend to make.

Re: Equifax securities fraud class action [pdf]

#146

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

No, Eric holder's legacy will be not going after bankers because that could hurt the economy. His solution was to rather leave the criminals in place instead of suffering any sort of short term pain (if that).

Re: Equifax securities fraud class action [pdf]

#148

If all software automatically changed its own admin password after 121 days, and refused to set old passwords (store the last 5 salted hash), that might be a good enough stick to force people to rotate passwords themselves, and default passwords would go away.

And users rotate their same "password1", "password2", "password3" passwords every expiration period...

Re: Equifax securities fraud class action [pdf]

#149

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

>changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost.

This policy change could also perhaps be attributed to lobbyists seeking to maximize profits and minimize risks for corporate clients who are knowingly breaking the law.

Re: Equifax securities fraud class action [pdf]

#150
Is there some nuance to this admin/admin used to access a portal?

I can completely imagine a headline like this when there is an old basic auth overlaying an application with a real password. It just seems unlikely that all the logging in the customer service portal will say, "updated by admin".

Post reply on HN