Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

181–190 of 227 posts

Re: Equifax securities fraud class action [pdf]

#181
post #120

Earlier quoted context omitted.

Unfortunately if there were such audits, I can practically guarantee that it would end up being bottom-dollar devs employed through unions or insider dealings. And the larger companies like equifax would likely have a deal allowing them to self audit to some extent. See: Boeing, iso certifications, building inspectors, health inspectors, any large civil engineering or aero firm, etc. To be clear, I do agree that it i…

Not accusing you of this, strictly speaking, but I see this as just more of the "if you regulate, they'll just do X, so don't bother" defeatism that is used all the time to argue against regulation, taxation, or any sort of policing of the rich and powerful. We have numerous examples of regulations actually working as designed. Notable failures (e.g. the IRS, the financial industry in the 2000s) are due in large part…

Yes, it always comes down to funding. But the major anti regulation party has also been staunchly anti tech regulation for a long time (link below), and even when the major tech companies tried to throw their weight around they lost (see Google et al vs fcc during the repeal of net neutrality). This can also be seen with the recent public appearances of govt harassment/scapegoating of facebook, which looks like "hey, we'd like you to change your rules" while simultaneously not regulating them. I think the first step needs to be a bit of a cultural shift towards regulation again before it will be effective (see epa push after the Ohio River caught fire). I don't mean to say "don't regulate, it's pointless", I mean to say "set it up from the top down, don't try to piggyback data regulation onto a framework that wasn't designed for it".

https://en.m.wikipedia.org/wiki/Office_of_Technology_Assessm...

Re: Equifax securities fraud class action [pdf]

#182
post #148

If all software automatically changed its own admin password after 121 days, and refused to set old passwords (store the last 5 salted hash), that might be a good enough stick to force people to rotate passwords themselves, and default passwords would go away.

And users rotate their same "password1", "password2", "password3" passwords every expiration period...

its easy to let them type old password then new password twice, that way u can confirm it's not similar to old password atleast since u receive it in unhashed form from the user themselves.

Re: Equifax securities fraud class action [pdf]

#183
post #8

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

Colleague #437: "So whoever first set this up has left, so I'll just follow the documentation they left to figure out what they did... Oh. ...eh, I got a deadline."

Re: Equifax securities fraud class action [pdf]

#184
post #120

Earlier quoted context omitted.

Unfortunately if there were such audits, I can practically guarantee that it would end up being bottom-dollar devs employed through unions or insider dealings. And the larger companies like equifax would likely have a deal allowing them to self audit to some extent. See: Boeing, iso certifications, building inspectors, health inspectors, any large civil engineering or aero firm, etc. To be clear, I do agree that it i…

I recently had some building work done. I was shocked (shocked!) to learn that the "municipal" inspector of works was a private individual, who was paid directly by the building company. Not by me - by the company that was supposedly being monitored. I didn't even have his name and address. [Edit: I am in the UK]

Wow, I always thought the UK was more focused on govt oversight than the US. Here in the US, building inspections have to be organized through government/municipal agencies. Whether they are subcontracted out is related to the size of the city/county but I know in at least 2 medium-large cities (250k-500k people) they have dedicated building inspectors on the payroll as govt employees.

Edit: Of course it would be irresponsible to say that they were consistent. Each inspector has their own ideas of "that should really be 2x12, not 2x10", or "that stairway is too steep", or "that should look more like the other houses", etc. But I do see value in forcing everyone facing a semi consistent set of rules.

Re: Equifax securities fraud class action [pdf]

#185

I'm using that headline as our thought of the day in group chat at work. Because that is just egregious and negligent. Nobody thought to raise that? to anyone? Although I can understand. I have several people who now call themselves DevOps on a project who have practically zero experience with systems operations _or_ development, and have done some utterly incomprehensibly stupid things. It doesn't matter how fancy y…

> Nobody thought to raise that? to anyone? Unbelievable, no? And yet, when things like this happen, people want to blame the CEO. Sure, the buck stops there and that person is really responsible for everything . But should the executives really be concerning themselves with the database password? It's an utterly irresponsible thing, and those actually working on the product should have known better. Unpopular opinion…

Maybe not the specifics, but "get a passing security audit" is high-level enough that a CEO might consider it important.

Re: Equifax securities fraud class action [pdf]

#186

Earlier quoted context omitted.

I am admittedly not the most educated person in this area (I wasn't 100% sure that "rule 10b5-1" was the rule that applied here), so I'd like to learn more. Can you give me an example of a reason you'd pre-arrange the sale of stock but not do it in accordance with Rule 10b5-1?

Arranging some other transaction (e.g. buying a yacht) in advance that would require cash, so the executive plans in advance a single sale to execute just ahead of the need for cash. If we go with the yacht purchase, perhaps in six months the builder needs final payment, so Mr. Executive arranges for a single sale of company stock a couple weeks before that date. Maybe such a thing does indeed require amending The Pl…

Not an expert either, but if such a thing was allowed, you could arrange to buy expensive stuff you want to have on a regular basis (I would assume this is not uncommon for CEOs) and then just agree orally with the seller to cancel the transactions when the stock is down, go through with it when the stock is up.

Re: Equifax securities fraud class action [pdf]

#187
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

I integrate with gov systems, very little PII, but we have to carry heavy insurance and get external audits every three years.

Re: Equifax securities fraud class action [pdf]

#188
post #160

Earlier quoted context omitted.

While nothing is impervious that really has nothing to do with Equifax. Equifax is a case of gross negligence and malfeasance. There were no less than three security audits of Equifax going back as early as 2014. Every audit indicated major security vulnerabilities and Smith disregarded these audits each time.

Who was paying for the security reviews if they were just going to be ignored? Some management or regulatory process?

A little bit of both. Equifax (and other credit reporting agencies) are subject to an annual audit from the SEC. There were issues being raised from the SEC with Equifax's processes going back to at least 2012. Ernst & Young also had a responsibility of oversight for Equifax's security practices due to acting as Equifax's primary independent auditor with regards to shareholder reporting.

Additionally, Equifax then paid on three separate occasions for external security audits at the direction of upper management (one specifically directed by Smith where the auditors were specifically directed to report the results only to Smith).

I haven't seen enough information to give a positive answer, but only to make conjecture that the external audits were driven by outside pressures; likely coming from the SEC. So the audits were performed, but this was essentially just a formality and management largely disregarded the audit findings.

Re: Equifax securities fraud class action [pdf]

#189

Earlier quoted context omitted.

Alternative reference is Spaceballs: Dark Helmet's locker combination.

Except this one was at least a 6 digit pass code rather than the four digit 1234 from Spaceballs. At least give them that credit?

Good point, that is 10 x 10 = 100 times safer!

Re: Equifax securities fraud class action [pdf]

#190
I tried setting up credit freezes at all 3 credit agencies as a result of the law making it free in the wake of the Equifax breach.

It took maybe 5 minutes at Experian and Transunion. Equifax's site 500'd when I attempted to set it up, and they had no way to take a report. When I called them on the phone, they suggested I send them a fax, and their customer service rep suggested I was a useless person who would never go anywhere in life when I said that was unacceptable and they should be out of business.

They should go out of business.

Post reply on HN