I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).
I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".
Equifax securities fraud class action [pdf]
211–220 of 227 posts
Re: Equifax securities fraud class action [pdf]
#212> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…
It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…
> Prosecution rates against crimes by large financial institutions are at 20-year lows. Holder has also endorsed the notion that prosecutors, when deciding to pursue white-collar crimes, should give special consideration to "collateral consequences" of bringing charges against large corporate institutions, as outlined in a 1999 memorandum by Holder. Nearly a decade later Holder, as head of the Department of Justice, put this into practice and has demonstrated the weight "collateral consequences" has by repeatedly sought and reached deferred prosecution and non-prosecution agreements and settlements with large financial institutions such as J.P. Morgan Chase, HSBC, Countrywide Mortgage, Wells Fargo, Goldman Sachs, and others where the institution pays a fine or penalty but faces no criminal charges and admits no wrongdoing. Whereas in the previous decade the Bush administration's Department of Justice often sought criminal charges against individuals of large institutions regardless of "collateral consequences" such as cases involving Enron, Adelphia Communications Corporation, Tyco International, and others.
https://en.wikipedia.org/wiki/Eric_Holder#Criminal_investiga...
Re: Equifax securities fraud class action [pdf]
#213> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…
It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…
Only for entities which are wealthy enough to effectively defend themselves against the awesome power of federal prosecution!
Re: Equifax securities fraud class action [pdf]
#214Earlier quoted context omitted.
It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…
>changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. This policy change could also perhaps be attributed to lobbyists seeking to maximize profits and minimize risks for corporate clients who are knowingly breaking the law.
Re: Equifax securities fraud class action [pdf]
#215Is there some nuance to this admin/admin used to access a portal? I can completely imagine a headline like this when there is an old basic auth overlaying an application with a real password. It just seems unlikely that all the logging in the customer service portal will say, "updated by admin".
Re: Equifax securities fraud class action [pdf]
#216Earlier quoted context omitted.
It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…
> On March 6, 2013, Holder testified to the Senate Judiciary Committee that the size of large financial institutions has made it difficult for the Justice Department to bring criminal charges when they are suspected of crimes, because such charges can threaten the existence of a bank and therefore their interconnectedness may endanger the national or global economy. "Some of these institutions have become too large,"…
Also I get that it's Wikipedia, but the comparison to Bush is ridiculous. The Enron story is a long one. Here's Gray Davis's perspective on exactly what it means that the Bush DoJ "sought criminal charges:"
> "I inherited the energy deregulation scheme which put us all at the mercy of the big energy producers. We got no help from the Federal government. In fact, when I was fighting Enron and the other energy companies, these same companies were sitting down with Vice President Cheney to draft a national energy strategy."
Furthermore the whole reason Holder is using the term "collateral consequences" instead of "collateral damage" is because that term was used by Dick Cheney and the press to describe why he does not care about civilian deaths in Afghanistan and later Iraq. It would be a stretch, but surely the lack of investigations into no-bid war contracts like Halliburton's had as much to do with their "collateral consequences" on military operations as it would on their paychecks.
Obama inherited multiple quagmires due to disregard of the consequences of criminal justice policy.
Normal people will never be on the wrong side of a banking fraud, except if their bank goes out of business. What is justice there?
So while I believe bad people should go to jail, I sympathize with Holder's point of view.
Re: Equifax securities fraud class action [pdf]
#217Earlier quoted context omitted.
There could be whistleblower protections for hackers. Consider the previous attitude was hackers are causing millions of dollars of damage and need to be thrown in prison. With the proliferation of state sponsored and counter intelligence hacking over the past 15 years, no one believes you can make anything secure just by throwing enough teenage script kiddies in federal prison. The reverse now is companies are takin…
While nothing is impervious that really has nothing to do with Equifax. Equifax is a case of gross negligence and malfeasance. There were no less than three security audits of Equifax going back as early as 2014. Every audit indicated major security vulnerabilities and Smith disregarded these audits each time.
Re: Equifax securities fraud class action [pdf]
#218Earlier quoted context omitted.
The difference is pretty big because there are a couple of conflicting things with the regulatory regime: it must be predictable (if things change rapidly, it becomes hard to comply and you'll get defacto non-compliance and shadow data storage) and it must be up to date. Policy makers usually don't specifically want punishments or changes in behaviour, they want outcomes. In a liability environment, you attempt to de…
Password Rotation and stagnant security practises are IMO a result of liablity environments, not regulatory environments.
Re: Equifax securities fraud class action [pdf]
#219Earlier quoted context omitted.
Password Rotation and stagnant security practises are IMO a result of liablity environments, not regulatory environments.
If instead of liability, you had a regulation mandating the implementation of specific guidelines, they'd use the ones produced by NIST, which until 2017 also recommended password rotation.
Re: Equifax securities fraud class action [pdf]
#220Earlier quoted context omitted.
As opposed to? The CIO is generally overseeing everything IT.
Probably as opposed to calling the CFO "the finance guy" in the same sentence as "the IT guy".