Live data from Hacker News

How Equifax Was Breached in 2017

blog.0x7d0.dev

11–20 of 117 posts

Re: How Equifax Was Breached in 2017

#12

TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s

Why "snakeoil"? Sounds like the system actually caught the intrusion once operable! The fact it was silently down for god knows how long is another matter...

> Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified?

You probably already know that these are compliance CYA focused around process not actual measure of how secure the system is (if there could be such a thing).

Re: How Equifax Was Breached in 2017

#13

TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s

Does the use of snakeoil in the TLDR not run contrary to the narrative in the blog? When the 'snakeoil MITM' certificate was updated - they became aware of, as a direct result of MITM, a problem that had not previously been known to them?

Re: How Equifax Was Breached in 2017

#15
post #2

If any company deserves the corporate death penalty, it's Equifax after this fiasco. That company should no longer exist.

Yes, the punishment should be immense. But we all know there's no real justice to be had here.

In places like China, there's personal accountability at the highest level of an org for major screw ups - sometimes even capital punishment.

If we put such options on the table here, perhaps corporations would be a little less callous with people's private data, and a little less eager to collect it.

Re: How Equifax Was Breached in 2017

#16

Wasn't Equifax Chief of Security a Music major? That was hilarious to read about...

I have met quiet a few people with no-tech degrees that made it in computer related IT fields. This alone is not an issue, but she hadn’t seem to have much experience in security at all.

Re: How Equifax Was Breached in 2017

#17

TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s

Why "snakeoil"? Sounds like the system actually caught the intrusion once operable! The fact it was silently down for god knows how long is another matter... > Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? You probably already know that these are compliance CYA focused around process not actual measure of how secure the system is (if there could be such a thing).

Snakeoil is a term for self-signed certs. I think they were lamenting the fact that it was not updated, not that it was self-signed.

https://eleni.blog/2019/04/10/the-snakeoil-ssl-certificate/

Re: How Equifax Was Breached in 2017

#18

TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s

Personally I think the root cause of this was bad documentation practices. If the old system was properly documented they would've scanned the right folder.

Likewise with the certificate, if there was documentation to indicate when that cert expires (or monitoring to alert few weeks in advance) they would have a functioning ids and these web shells would be found immediately.

Unfortunately, out of half a dozen fortune 500 companies I worked for perhaps 2 had doc practices good enough to prevent this.

Re: How Equifax Was Breached in 2017

#20

Wasn't Equifax Chief of Security a Music major? That was hilarious to read about...

Music major CTO here. Jog on. God forbid our executives be trained in creativity.

Most CXOs have extensive experience in their relevant fields. Your retort seems needlessly defensive.
Post reply on HN