Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

171–180 of 227 posts

Re: Equifax securities fraud class action [pdf]

#171

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

Security is a cost and nuisance. It's the first thing to be cut. To keep high security at all times you need: 1) Process aka bureaucracy. Mandatory checklists. Checklists are returned and inspected by others. Anything missing or uncertain is checked again and fixed. 2) People who are responsible for security are independent from other concerns. They can have adversarial relationship with people responsible for gettin…

True. The market cannot reward what it cannot see.

Re: Equifax securities fraud class action [pdf]

#172

Earlier quoted context omitted.

I am admittedly not the most educated person in this area (I wasn't 100% sure that "rule 10b5-1" was the rule that applied here), so I'd like to learn more. Can you give me an example of a reason you'd pre-arrange the sale of stock but not do it in accordance with Rule 10b5-1?

Arranging some other transaction (e.g. buying a yacht) in advance that would require cash, so the executive plans in advance a single sale to execute just ahead of the need for cash. If we go with the yacht purchase, perhaps in six months the builder needs final payment, so Mr. Executive arranges for a single sale of company stock a couple weeks before that date. Maybe such a thing does indeed require amending The Pl…

Yeah, I would assume that something like that would also be done within Rule 10b5-1, but that has hidden assumptions that I know nothing about, like that it's not just "the plan" but multiple plans, etc. Anyway, thanks.

Re: Equifax securities fraud class action [pdf]

#173
post #90
post #82

Earlier quoted context omitted.

There are two types of possible regulation, one is control and the other is liability. With control, some administrative body says you have to do X, Y and Z. And presumably, if you jump through the hoops and it blows up, there is an implicit guarantee. This kind of regulation is common across banks, and in 2008 when all the reserve requirements were deemed insufficient and all the acceptable ratings meaningless, ther…

I don't see much difference in the two approaches, except the later case will require customers to collectively sue you for damages, in which case you can probably run a cost-benefit analysis to find out if it would be worth it. In a regulatory environment, if a corporation does not comply, the punishment is increased until either the corporation complies or seizes to exist. Since not existing is bad for profit, corp…

The big operative difference is that under the Control regime, the regulator decides what practices are acceptable. Under the Liability regime, the acceptability of practices depends more directly on their effectiveness (with more or less directness depending on the type of liability).

A Liability regime would encourage companies to be actually secure, because they're responsible for what happens to data that is lost. A Control regime would encourage companies to check boxes from a list provided by a regulator. A Liability regime encourages being pro-active vs reactive to the regulator in a Control regime.

There are middle grounds, like HIPAA or GDPR. Both give companies some leeway in terms of creating their own checkboxes, and fines are for actual breaches, not just improper process.

Re: Equifax securities fraud class action [pdf]

#174
post #173
post #90

Earlier quoted context omitted.

I don't see much difference in the two approaches, except the later case will require customers to collectively sue you for damages, in which case you can probably run a cost-benefit analysis to find out if it would be worth it. In a regulatory environment, if a corporation does not comply, the punishment is increased until either the corporation complies or seizes to exist. Since not existing is bad for profit, corp…

The big operative difference is that under the Control regime, the regulator decides what practices are acceptable. Under the Liability regime, the acceptability of practices depends more directly on their effectiveness (with more or less directness depending on the type of liability). A Liability regime would encourage companies to be actually secure , because they're responsible for what happens to data that is los…

In my experience, liability doesn't make anything secure (see: Health Sector), it just makes people afraid to innovate.

Re: Equifax securities fraud class action [pdf]

#175

Earlier quoted context omitted.

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

I'd like to defend Eric Holder. It's no secret what he does or who he works for. He's a lawyer that works for the big banks and other powerful industries, his job is literally to keep them out of legal trouble. We should be pointing the finger at the people who knew all these things and still put him in charge of the justice department. We should also be pointing the finger at the ones who have the power to change th…

Nah, doing that might actually prevent things like this from happen, so we should all downvote you instead.

Re: Equifax securities fraud class action [pdf]

#176
post #120
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Unfortunately if there were such audits, I can practically guarantee that it would end up being bottom-dollar devs employed through unions or insider dealings. And the larger companies like equifax would likely have a deal allowing them to self audit to some extent. See: Boeing, iso certifications, building inspectors, health inspectors, any large civil engineering or aero firm, etc. To be clear, I do agree that it i…

I recently had some building work done.

I was shocked (shocked!) to learn that the "municipal" inspector of works was a private individual, who was paid directly by the building company. Not by me - by the company that was supposedly being monitored. I didn't even have his name and address.

[Edit: I am in the UK]

Re: Equifax securities fraud class action [pdf]

#177
"Was that wrong? Should I have not done that? I tell you, I gotta plead ignorance on this thing because if anyone had said anything to me at all when I first started here that that sort of thing was frowned upon, you know, ‘cause I've worked in a lot of offices and I tell you people do that all the time."

Re: Equifax securities fraud class action [pdf]

#178
post #81
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Its probably been admin/admin for the past decade as well

since it's using regular admin credz, a lot of prior 'breaches' might even have gone unnoticed, since its likely no alarm bells would have been in place to find authorised access misuse.

Re: Equifax securities fraud class action [pdf]

#179

Earlier quoted context omitted.

Apparently both execs have been cleared of an insider trading charge. https://gizmodo.com/equifax-investigation-clears-execs-who-d...

Basically "We investigated ourselves and found there was no wrongdoing." As the top comment there notes, they're positing that the director of US Information Security wasn't aware of the data breach until 2 weeks after it was uncovered.

"hey man, we're all selling our shares, but we can't tell you why"

Re: Equifax securities fraud class action [pdf]

#180

Scrolling through the comments I'm surprised (and not all at the same time) no one has made a comment like this: So what? If an attacker is able to reach your DB the ballgame at 90% of the way over already. Yes I understand that a strong U/P on the DB server would be 1 final gate but unless I'm living in some alternative reality I can tell you plenty of companies use weak/shared/guessable passwords for stuff that sho…

Right, the username/password is easy to point to as an obvious problem, but surely this wasn't the _only_ security hole the hackers had to get through, right?

I can't imagine a secure database password would have prevented the hack.

Though the lack of a secure database password probably hints at Equifax's attitude toward security in general.

Post reply on HN