Live data from Hacker News

How Equifax Was Breached in 2017

blog.0x7d0.dev

31–40 of 117 posts

Re: How Equifax Was Breached in 2017

#31

Didn't Equifax receive practically no penalty for it though? So, what would be the motivation to avoid future things like this happening again?

You should read the approved judgements with the various State AGs that outline the measures, Government oversight and reporting Equifax is still required to do to prevent a future occurrence.

Should it happen again then you would very likely hear for calls for Gov to step in and take direct control of the firm.

Re: How Equifax Was Breached in 2017

#32
Not mentioned here was that the group that exploited the vulnerability handed over to PLA linked individuals who then conducted the exfiltration.

https://www.justice.gov/opa/pr/chinese-military-personnel-ch...

As far as I am aware the data has never been seen on the open market, so there's a whole other National Security story around whether the information was used to compromise individuals with credit issues for commercial and military espionage purposes. It would seem that this was known very early on and possibly factored into the settlement.

Re: How Equifax Was Breached in 2017

#33
post #31

Didn't Equifax receive practically no penalty for it though? So, what would be the motivation to avoid future things like this happening again?

You should read the approved judgements with the various State AGs that outline the measures, Government oversight and reporting Equifax is still required to do to prevent a future occurrence. Should it happen again then you would very likely hear for calls for Gov to step in and take direct control of the firm.

> Should it happen again then you would very likely hear for calls for Gov to step in and take direct control of the firm.

We heard calls for similar last time, but I don't think anybody expected the legal/regulatory response to be anything resembling an existential threat to Equifax, and it wasn't. I don't see why the second time would be any different—we are surrounded by examples of how our dogshit government is utterly derelict in its duty to protect workers and consumers, and arguably complicit across the vast scope of corporate abuse of the same.

Re: How Equifax Was Breached in 2017

#35

Earlier quoted context omitted.

Well, the process itself cannot be working because otherwise this whole fiasco would have been found. Technically within 24 hours, if the certifications are to be believed. Trying to defend a broken process isn't what this is about, my critic was about that there was an audit a decade ago, and that the auditors did not verify any of the claims or processes in place. Certifications and audits without any verification…

Common misunderstanding about 27001 - it doesn’t have mandatory anything when it comes to security controls. It defines how you structure and operate a risk based security management system, that’s all. It’s perfectly valid to say “I should be doing pen testing but my risk appetite is high enough for me not to care”, and still get a 27001 certification.

> “I should be doing pen testing but my risk appetite is high enough for me not to care”, and still get a 27001 certification.

I would agree with you if Equifax wouldn't be part of critical infrastructure.

Re: How Equifax Was Breached in 2017

#36
post #28

> Malicious actors had been exfiltrating data for several months and had already collected personal information from 163 million customers. I don't think "customers" is the right term, considering I never wanted them collecting data about me.

Yes, this is what most people don't understand with data breaches: it's not the company's data, it's data on others. That's why they don't really care about protecting it.

That is not correct for a data brokerage as the data is the business. Lose your monopoly on that data and you have no business.

If it is information collected as part of doing business, then yes; they don't care. A good reason to question any Gov attempt to implement centralisation of data like identity or medical records.

Re: How Equifax Was Breached in 2017

#37
post #31

Earlier quoted context omitted.

You should read the approved judgements with the various State AGs that outline the measures, Government oversight and reporting Equifax is still required to do to prevent a future occurrence. Should it happen again then you would very likely hear for calls for Gov to step in and take direct control of the firm.

> Should it happen again then you would very likely hear for calls for Gov to step in and take direct control of the firm. We heard calls for similar last time, but I don't think anybody expected the legal/regulatory response to be anything resembling an existential threat to Equifax, and it wasn't. I don't see why the second time would be any different—we are surrounded by examples of how our dogshit government is u…

When anyone talks about Equifax's "customers" that means Government at all levels along with every corporate who isn't using a competitor. I would think a takeover similar to what happened with Fannie Mae/Freddy Mac could happen as much to maintain Equifax as a going concern and protect the credit markets than an actual penalty. Consumers still get screwed.

Re: How Equifax Was Breached in 2017

#38

> Malicious actors had been exfiltrating data for several months and had already collected personal information from 163 million customers. I don't think "customers" is the right term, considering I never wanted them collecting data about me.

I did some contract work for another credit agency many moons ago and they pretty much brainwashed all full time staff into referring to data subjects as customers. A fellow contractor made a very snide analogy of suggesting that the Nazis could have called Jews customers to legitimise their actions. None of us renewed. Horrible place.

Re: How Equifax Was Breached in 2017

#39
I really appreciate detailed breach reports like this. This was the money quote for me:

> The attackers continued their search and eventually discovered a mounted NFS share on the web server. This file share contained notes and configuration files used by Equifax engineers, in which they found many database credentials.

Seriously, WTF? I get paranoid all the time worrying about my application security - it often feels like there is always some potential issue around the corner you don't know about.

But then I read about how lots of these kinds of breaches occur (storing prod DB credentials in plaintext on an NFS share, reusing passwords and not using 2FA, leaving your server password as "solarwinds123", etc.) and I think maybe I'm not so bad after all.

Re: How Equifax Was Breached in 2017

#40
post #36
post #28

Earlier quoted context omitted.

Yes, this is what most people don't understand with data breaches: it's not the company's data, it's data on others. That's why they don't really care about protecting it.

That is not correct for a data brokerage as the data is the business. Lose your monopoly on that data and you have no business. If it is information collected as part of doing business, then yes; they don't care. A good reason to question any Gov attempt to implement centralisation of data like identity or medical records.

> Lose your monopoly on that data and you have no business.

But do these breaches affect their monopoly? My thinking is:

1. B2B customers won't go on darknet to source illegal data dumps.

2. This data, even if it doesn't quickly become effectively stale, would be considered stale by businesses very quickly if it's not connected to the continuous data ingestion pipeline.

Post reply on HN