Live data from Hacker News

How Equifax Was Breached in 2017

blog.0x7d0.dev

41–50 of 117 posts

Re: How Equifax Was Breached in 2017

#41
post #32

Not mentioned here was that the group that exploited the vulnerability handed over to PLA linked individuals who then conducted the exfiltration. https://www.justice.gov/opa/pr/chinese-military-personnel-ch... As far as I am aware the data has never been seen on the open market, so there's a whole other National Security story around whether the information was used to compromise individuals with credit issues for co…

Also mis-mentioned, is that I heard nothing was "missed" but security upgrades were not possible due to the age of the stack.

Pre-0 days are one thing. But leaving systems unpatched for months, because your stack is too old, is a common, but inexcusable theme.

This is why it is vital to use libraries, frameworks, with a stable, unchanging LTS branch. Failure to do so, means a security update that needs to be applied instantly, cannot be done, without extensive app changes.

New shiny is fine. But it must never, ever override basic security concerns.

Security comes first. Not last. Always.

Re: How Equifax Was Breached in 2017

#42
post #36
post #28

Earlier quoted context omitted.

Yes, this is what most people don't understand with data breaches: it's not the company's data, it's data on others. That's why they don't really care about protecting it.

That is not correct for a data brokerage as the data is the business. Lose your monopoly on that data and you have no business. If it is information collected as part of doing business, then yes; they don't care. A good reason to question any Gov attempt to implement centralisation of data like identity or medical records.

> Lose your monopoly on that data and you have no business.

Could you elaborate on how Equifax would have gone out of business if all their data had been stolen?

Re: How Equifax Was Breached in 2017

#43
post #31

Didn't Equifax receive practically no penalty for it though? So, what would be the motivation to avoid future things like this happening again?

You should read the approved judgements with the various State AGs that outline the measures, Government oversight and reporting Equifax is still required to do to prevent a future occurrence. Should it happen again then you would very likely hear for calls for Gov to step in and take direct control of the firm.

So, treated the same way as banks after the GFC then, but without needing to give them money as well?

Re: How Equifax Was Breached in 2017

#44
post #25

Didn't Equifax receive practically no penalty for it though? So, what would be the motivation to avoid future things like this happening again?

A tiny penalty. The CIO got a $3M bonus, too. Odd thing is that she had a music degree and little experience in IT, but was an old friend of the board members.

Not enough downvotes for this. I'm assuming this is all BS considering you got all the details wrong. It was the CEO who got a $3 million bonus in 2016, not the CIO. Susan Mauldin, who earned a music degree in college, was the Equifax CISO, not their CIO.

The reason I'm so salty about your response is when the breach happened, there were tons of news reports denigrating the CISO because she had a music degree. There may be a ton of reasons she wasn't good at her job (though it's hard to say as CISO is often a "sacrificial lamb" job anyway), and I'm certainly not defending Equifax, but I take major issue with the implication that a music degree makes someone unqualified for a tech job.

First, as she was CISO, she was presumably done with college many, many years ago. Lots of people have college degrees that aren't necessarily directed to the career they end up in. More importantly, though, I've found that there is a direct correlation between highly trained musicians and great software engineers. I don't know if it's a "same part of the brain" thing or whatever, but I'm actually astounded at the sheer number of "best of the best" software engineers I've worked with that are classically trained musicians. It's to the point that when hiring I give "extra points" if you will to musicians because, it my experience at least, the correlation is so strong.

So, frankly, you can take your "she had a music degree" shade and shove it.

Re: How Equifax Was Breached in 2017

#45

I really appreciate detailed breach reports like this. This was the money quote for me: > The attackers continued their search and eventually discovered a mounted NFS share on the web server. This file share contained notes and configuration files used by Equifax engineers, in which they found many database credentials. Seriously, WTF? I get paranoid all the time worrying about my application security - it often feel…

I'm totally with you on this one; but remember, if you have 25 developers in groups of 5, in only takes 1 muppet in any of the 5 groups to have low standards, and voila.

I've seen it, in pretty much every large business I've worked in.

This goes back to the saying: "you should never hire someone less good than yourself".

Sadly when the people hiring literally come from sales or airline customer service, your company is boned. It's only a matter of time.

Re: How Equifax Was Breached in 2017

#46

Wasn't Equifax Chief of Security a Music major? That was hilarious to read about...

A lot of people in security don’t have a degree at all, let alone in computer science. Judging people’s qualifications is much more complicated than just looking at their degree.

Re: How Equifax Was Breached in 2017

#47
post #22

Earlier quoted context omitted.

Music major CTO here. Jog on. God forbid our executives be trained in creativity.

As long as you're also trained in IT...

You mean college-trained? Because GP is a CTO, so I guess he has experience. I don't respect the C-suite that much, but I've never seen CTO without solid SWE knowledge.

Re: How Equifax Was Breached in 2017

#48
post #45

I really appreciate detailed breach reports like this. This was the money quote for me: > The attackers continued their search and eventually discovered a mounted NFS share on the web server. This file share contained notes and configuration files used by Equifax engineers, in which they found many database credentials. Seriously, WTF? I get paranoid all the time worrying about my application security - it often feel…

I'm totally with you on this one; but remember, if you have 25 developers in groups of 5, in only takes 1 muppet in any of the 5 groups to have low standards, and voila. I've seen it, in pretty much every large business I've worked in. This goes back to the saying: "you should never hire someone less good than yourself". Sadly when the people hiring literally come from sales or airline customer service, your company…

I agree with all that, with the one small caveat that more than anything else I think what is most important about security is a strong security culture at a company. All the checklists and compliance frameworks in the world are doomed in the face of a poor security culture. On the flip side, a strong and constantly reinforced security culture can help protect against the occasional muppet.

One example: years ago I started work at a tech company (a fintech no less), and shortly after starting I asked the head of customer service how I could get an account to access an internal admin portal (I was an engineer and needed to understand some of ops processes). "Oh, you just log in with my account, and the password is - all the reps just use that shared account" I got an immediate sinking, sinking feeling of despair.

Re: How Equifax Was Breached in 2017

#49
post #25

Earlier quoted context omitted.

A tiny penalty. The CIO got a $3M bonus, too. Odd thing is that she had a music degree and little experience in IT, but was an old friend of the board members.

Not enough downvotes for this. I'm assuming this is all BS considering you got all the details wrong. It was the CEO who got a $3 million bonus in 2016, not the CIO. Susan Mauldin, who earned a music degree in college, was the Equifax CISO, not their CIO. The reason I'm so salty about your response is when the breach happened, there were tons of news reports denigrating the CISO because she had a music degree. There…

I've worked with several senior people ("Principal Enterprise Architect", etc...) who were music majors, and as a rule they were terrible at their jobs. They just... didn't care about anything even vaguely related to computers. Without exception they got into their positions through nepotism, ass-kissing, or dirty politics. None got there through talent.

People who like computers do it as a hobby. They learn programming at a young age, they get a CS degree or a hard science degree, and then they spend their spare time on tech forums like HN.

People who don't like computers play music, learn painting, or do something else. They get degrees in the arts or humanities. They spend their spare time playing music at the local pub, or whatever.

PS: One of the worst programmers I had ever met is also one of the best musicians I had ever met.

Re: How Equifax Was Breached in 2017

#50
post #45

Earlier quoted context omitted.

I'm totally with you on this one; but remember, if you have 25 developers in groups of 5, in only takes 1 muppet in any of the 5 groups to have low standards, and voila. I've seen it, in pretty much every large business I've worked in. This goes back to the saying: "you should never hire someone less good than yourself". Sadly when the people hiring literally come from sales or airline customer service, your company…

I agree with all that, with the one small caveat that more than anything else I think what is most important about security is a strong security culture at a company. All the checklists and compliance frameworks in the world are doomed in the face of a poor security culture. On the flip side, a strong and constantly reinforced security culture can help protect against the occasional muppet. One example: years ago I s…

Better than culture is enforced guarantees, nobody can store the database password on an NFS share if it's not available to them.
Post reply on HN