If any company deserves the corporate death penalty, it's Equifax after this fiasco. That company should no longer exist.
How Equifax Was Breached in 2017
11–20 of 117 posts
Re: How Equifax Was Breached in 2017
#12TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s
> Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified?
You probably already know that these are compliance CYA focused around process not actual measure of how secure the system is (if there could be such a thing).
Re: How Equifax Was Breached in 2017
#13TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s
Re: How Equifax Was Breached in 2017
#14That was hilarious to read about...
Re: How Equifax Was Breached in 2017
#15If any company deserves the corporate death penalty, it's Equifax after this fiasco. That company should no longer exist.
In places like China, there's personal accountability at the highest level of an org for major screw ups - sometimes even capital punishment.
If we put such options on the table here, perhaps corporations would be a little less callous with people's private data, and a little less eager to collect it.
Re: How Equifax Was Breached in 2017
#16Wasn't Equifax Chief of Security a Music major? That was hilarious to read about...
Re: How Equifax Was Breached in 2017
#17TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s
Why "snakeoil"? Sounds like the system actually caught the intrusion once operable! The fact it was silently down for god knows how long is another matter... > Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? You probably already know that these are compliance CYA focused around process not actual measure of how secure the system is (if there could be such a thing).
Re: How Equifax Was Breached in 2017
#18TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s
Likewise with the certificate, if there was documentation to indicate when that cert expires (or monitoring to alert few weeks in advance) they would have a functioning ids and these web shells would be found immediately.
Unfortunately, out of half a dozen fortune 500 companies I worked for perhaps 2 had doc practices good enough to prevent this.
Re: How Equifax Was Breached in 2017
#19Wasn't Equifax Chief of Security a Music major? That was hilarious to read about...
God forbid our executives be trained in creativity.