Live data from Hacker News

How Equifax Was Breached in 2017

blog.0x7d0.dev

21–30 of 117 posts

Re: How Equifax Was Breached in 2017

#21

TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s

Why "snakeoil"? Sounds like the system actually caught the intrusion once operable! The fact it was silently down for god knows how long is another matter... > Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? You probably already know that these are compliance CYA focused around process not actual measure of how secure the system is (if there could be such a thing).

Well, the process itself cannot be working because otherwise this whole fiasco would have been found. Technically within 24 hours, if the certifications are to be believed.

Trying to defend a broken process isn't what this is about, my critic was about that there was an audit a decade ago, and that the auditors did not verify any of the claims or processes in place. Certifications and audits without any verification of claims are not valid certifications.

SOC2 and ISO27001 also include _mandatory_ pentests which obviously didn't happen that year. Either that or the pentesting agency wasn't actually doing more than a metasploit run ;)

Re: How Equifax Was Breached in 2017

#23
post #18

TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s

Personally I think the root cause of this was bad documentation practices. If the old system was properly documented they would've scanned the right folder. Likewise with the certificate, if there was documentation to indicate when that cert expires (or monitoring to alert few weeks in advance) they would have a functioning ids and these web shells would be found immediately. Unfortunately, out of half a dozen fortun…

[deleted]

Re: How Equifax Was Breached in 2017

#24
post #18

TLDR is: Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it. Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? Oh yeah, they probably have a checklist for that, so they must be secure. /s

Personally I think the root cause of this was bad documentation practices. If the old system was properly documented they would've scanned the right folder. Likewise with the certificate, if there was documentation to indicate when that cert expires (or monitoring to alert few weeks in advance) they would have a functioning ids and these web shells would be found immediately. Unfortunately, out of half a dozen fortun…

That feels like the wrong conclusion. Assuming documentation will be followed properly is not a reasonable security strategy. Validation and monitoring is needed. That their NIDS gracefully degraded to a "don't monitor the payloads" when it was expected that it would be monitoring those and nobody noticed is a problem. A scan of a system which misses a web server running it without erroring is a problem.

Re: How Equifax Was Breached in 2017

#25

Didn't Equifax receive practically no penalty for it though? So, what would be the motivation to avoid future things like this happening again?

A tiny penalty.

The CIO got a $3M bonus, too. Odd thing is that she had a music degree and little experience in IT, but was an old friend of the board members.

Re: How Equifax Was Breached in 2017

#26

Wasn't Equifax Chief of Security a Music major? That was hilarious to read about...

Music major CTO here. Jog on. God forbid our executives be trained in creativity.

There are different types of creativity. Working in security actually requires a lot of a specific type of imagination/creativity that pretty much isn't used anywhere else.

Re: How Equifax Was Breached in 2017

#27

Didn't Equifax receive practically no penalty for it though? So, what would be the motivation to avoid future things like this happening again?

I can’t remember what I got but yes it amounted to nothing. Free credit monitoring that had a million upsells and dark patterns meant to make them more money. That’s my recollection but it’s all fuzzy because we’ve all been breached so many times.

Re: How Equifax Was Breached in 2017

#28

> Malicious actors had been exfiltrating data for several months and had already collected personal information from 163 million customers. I don't think "customers" is the right term, considering I never wanted them collecting data about me.

Yes, this is what most people don't understand with data breaches: it's not the company's data, it's data on others. That's why they don't really care about protecting it.

Re: How Equifax Was Breached in 2017

#30

Earlier quoted context omitted.

Why "snakeoil"? Sounds like the system actually caught the intrusion once operable! The fact it was silently down for god knows how long is another matter... > Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified? You probably already know that these are compliance CYA focused around process not actual measure of how secure the system is (if there could be such a thing).

Well, the process itself cannot be working because otherwise this whole fiasco would have been found. Technically within 24 hours, if the certifications are to be believed. Trying to defend a broken process isn't what this is about, my critic was about that there was an audit a decade ago, and that the auditors did not verify any of the claims or processes in place. Certifications and audits without any verification…

Common misunderstanding about 27001 - it doesn’t have mandatory anything when it comes to security controls.

It defines how you structure and operate a risk based security management system, that’s all. It’s perfectly valid to say “I should be doing pen testing but my risk appetite is high enough for me not to care”, and still get a 27001 certification.

Post reply on HN