Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

211–220 of 227 posts

Re: Equifax securities fraud class action [pdf]

#211
post #8

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

You would be shocked at how nonchalant and downright negligent people can be about security at even the largest companies in the US. I did consulting work at a large insurance company that had the contact information, ssn, and PHI of pretty much everyone in the America (and I mean everyone). I lost track of the number of times people checked in the production password into git. In fact our production cassandra instance still was using the default cert password 'changeit' when I left. Unsurprisingly, this company was filled with contract workers and H1B workers that were barely able (if at all) to get their work done.

Re: Equifax securities fraud class action [pdf]

#212

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

> On March 6, 2013, Holder testified to the Senate Judiciary Committee that the size of large financial institutions has made it difficult for the Justice Department to bring criminal charges when they are suspected of crimes, because such charges can threaten the existence of a bank and therefore their interconnectedness may endanger the national or global economy. "Some of these institutions have become too large," Holder told the Committee, "It has an inhibiting impact on our ability to bring resolutions that I think would be more appropriate.

> Prosecution rates against crimes by large financial institutions are at 20-year lows. Holder has also endorsed the notion that prosecutors, when deciding to pursue white-collar crimes, should give special consideration to "collateral consequences" of bringing charges against large corporate institutions, as outlined in a 1999 memorandum by Holder. Nearly a decade later Holder, as head of the Department of Justice, put this into practice and has demonstrated the weight "collateral consequences" has by repeatedly sought and reached deferred prosecution and non-prosecution agreements and settlements with large financial institutions such as J.P. Morgan Chase, HSBC, Countrywide Mortgage, Wells Fargo, Goldman Sachs, and others where the institution pays a fine or penalty but faces no criminal charges and admits no wrongdoing. Whereas in the previous decade the Bush administration's Department of Justice often sought criminal charges against individuals of large institutions regardless of "collateral consequences" such as cases involving Enron, Adelphia Communications Corporation, Tyco International, and others.

https://en.wikipedia.org/wiki/Eric_Holder#Criminal_investiga...

Re: Equifax securities fraud class action [pdf]

#213

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

> Justice is now escapable because it's been deemed "too difficult to pursue"

Only for entities which are wealthy enough to effectively defend themselves against the awesome power of federal prosecution!

Re: Equifax securities fraud class action [pdf]

#214

Earlier quoted context omitted.

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

>changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. This policy change could also perhaps be attributed to lobbyists seeking to maximize profits and minimize risks for corporate clients who are knowingly breaking the law.

Sure, which is the fault of the people and the government, as far as I’m concerned. If an elected official is corrupted or doing something we disagree with, it’s our job to fix it.

Re: Equifax securities fraud class action [pdf]

#215
post #150

Is there some nuance to this admin/admin used to access a portal? I can completely imagine a headline like this when there is an old basic auth overlaying an application with a real password. It just seems unlikely that all the logging in the customer service portal will say, "updated by admin".

Maybe the portal software was priced by user count?

Re: Equifax securities fraud class action [pdf]

#216

Earlier quoted context omitted.

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

> On March 6, 2013, Holder testified to the Senate Judiciary Committee that the size of large financial institutions has made it difficult for the Justice Department to bring criminal charges when they are suspected of crimes, because such charges can threaten the existence of a bank and therefore their interconnectedness may endanger the national or global economy. "Some of these institutions have become too large,"…

This is missing the perspective of just how much a disaster Obama inherited in 2008.

Also I get that it's Wikipedia, but the comparison to Bush is ridiculous. The Enron story is a long one. Here's Gray Davis's perspective on exactly what it means that the Bush DoJ "sought criminal charges:"

> "I inherited the energy deregulation scheme which put us all at the mercy of the big energy producers. We got no help from the Federal government. In fact, when I was fighting Enron and the other energy companies, these same companies were sitting down with Vice President Cheney to draft a national energy strategy."

Furthermore the whole reason Holder is using the term "collateral consequences" instead of "collateral damage" is because that term was used by Dick Cheney and the press to describe why he does not care about civilian deaths in Afghanistan and later Iraq. It would be a stretch, but surely the lack of investigations into no-bid war contracts like Halliburton's had as much to do with their "collateral consequences" on military operations as it would on their paychecks.

Obama inherited multiple quagmires due to disregard of the consequences of criminal justice policy.

Normal people will never be on the wrong side of a banking fraud, except if their bank goes out of business. What is justice there?

So while I believe bad people should go to jail, I sympathize with Holder's point of view.

Re: Equifax securities fraud class action [pdf]

#217
post #60

Earlier quoted context omitted.

There could be whistleblower protections for hackers. Consider the previous attitude was hackers are causing millions of dollars of damage and need to be thrown in prison. With the proliferation of state sponsored and counter intelligence hacking over the past 15 years, no one believes you can make anything secure just by throwing enough teenage script kiddies in federal prison. The reverse now is companies are takin…

While nothing is impervious that really has nothing to do with Equifax. Equifax is a case of gross negligence and malfeasance. There were no less than three security audits of Equifax going back as early as 2014. Every audit indicated major security vulnerabilities and Smith disregarded these audits each time.

Are they actually worse than other companies? Or were they just the ones who got caught at it?

Re: Equifax securities fraud class action [pdf]

#218
post #202

Earlier quoted context omitted.

The difference is pretty big because there are a couple of conflicting things with the regulatory regime: it must be predictable (if things change rapidly, it becomes hard to comply and you'll get defacto non-compliance and shadow data storage) and it must be up to date. Policy makers usually don't specifically want punishments or changes in behaviour, they want outcomes. In a liability environment, you attempt to de…

Password Rotation and stagnant security practises are IMO a result of liablity environments, not regulatory environments.

If instead of liability, you had a regulation mandating the implementation of specific guidelines, they'd use the ones produced by NIST, which until 2017 also recommended password rotation.

Re: Equifax securities fraud class action [pdf]

#219
post #202

Earlier quoted context omitted.

Password Rotation and stagnant security practises are IMO a result of liablity environments, not regulatory environments.

If instead of liability, you had a regulation mandating the implementation of specific guidelines, they'd use the ones produced by NIST, which until 2017 also recommended password rotation.

There is no reason why regulatory bodies cannot be up-to-date with the latest developments.

Re: Equifax securities fraud class action [pdf]

#220

Earlier quoted context omitted.

As opposed to? The CIO is generally overseeing everything IT.

Probably as opposed to calling the CFO "the finance guy" in the same sentence as "the IT guy".

I call the CFO the money guy and the CEO the boss guy. I work at a pretty relaxed company though so it flies.
Post reply on HN