Live data from Hacker News

How Equifax Was Breached in 2017

blog.0x7d0.dev

61–70 of 117 posts

Re: How Equifax Was Breached in 2017

#61
post #31

Earlier quoted context omitted.

You should read the approved judgements with the various State AGs that outline the measures, Government oversight and reporting Equifax is still required to do to prevent a future occurrence. Should it happen again then you would very likely hear for calls for Gov to step in and take direct control of the firm.

So, treated the same way as banks after the GFC then, but without needing to give them money as well?

Could you imagine how well bailing out Equifax to pay its legal bills would go down?

Re: How Equifax Was Breached in 2017

#62

Earlier quoted context omitted.

Common misunderstanding about 27001 - it doesn’t have mandatory anything when it comes to security controls. It defines how you structure and operate a risk based security management system, that’s all. It’s perfectly valid to say “I should be doing pen testing but my risk appetite is high enough for me not to care”, and still get a 27001 certification.

> “I should be doing pen testing but my risk appetite is high enough for me not to care”, and still get a 27001 certification. I would agree with you if Equifax wouldn't be part of critical infrastructure.

Agreed - but 27001 doesn't have an opinion on that. It only requires that top management have set the context that the rest of the information security management system hangs off of. It doesn't specify what that context should be for your company.

It's completely unlike SOC in that regard.

Re: How Equifax Was Breached in 2017

#63
post #25

Earlier quoted context omitted.

A tiny penalty. The CIO got a $3M bonus, too. Odd thing is that she had a music degree and little experience in IT, but was an old friend of the board members.

Not enough downvotes for this. I'm assuming this is all BS considering you got all the details wrong. It was the CEO who got a $3 million bonus in 2016, not the CIO. Susan Mauldin, who earned a music degree in college, was the Equifax CISO, not their CIO. The reason I'm so salty about your response is when the breach happened, there were tons of news reports denigrating the CISO because she had a music degree. There…

It was also widely reported that she had no apparent security background, so maybe provide some evidence that the shade was unwarranted?

Of course lots of people get into tech from non tech but it's not a reason to go off on the commenter with an angry screed.

Also, she was CSO not CISO or CIO not that there's much of a difference between those titles in practice anyway.

Re: How Equifax Was Breached in 2017

#64

> Malicious actors had been exfiltrating data for several months and had already collected personal information from 163 million customers. I don't think "customers" is the right term, considering I never wanted them collecting data about me.

HMRC calls its pillaged subjects 'customers' - which gives me no end of amusement. I can't ever remember asking for their 'custom', nor do I remember them ever going out of their way to win it from me.

Re: How Equifax Was Breached in 2017

#65
post #61

Earlier quoted context omitted.

So, treated the same way as banks after the GFC then, but without needing to give them money as well?

Could you imagine how well bailing out Equifax to pay its legal bills would go down?

Does it matter if the worst happened? It will be irrelevant 24 hours later.

Re: How Equifax Was Breached in 2017

#66
post #50

Earlier quoted context omitted.

Better than culture is enforced guarantees, nobody can store the database password on an NFS share if it's not available to them.

I honestly believe that enforced guarantees come about through security culture though. Meaning a strong security culture means you do appropriate secrets management, and importantly, everyone understands how secrets management should be done. That way if you have the occasional breach in your automated enforced guarantees (e.g. the article talks about how Equifax missed one of their vulnerable systems to patch), tha…

I think you will love the way Microsoft handles this. Basically, there are automated flags that seem to ding managers (M1 I believe) so they will make sure the people in their teams handle these.

> any engineer on that team who came across an NFS file with DB credentials should have spoken up loudly about "Why TF are these DB credentials present on a network drive?"

This requires empowering your employees and the lower case a while with its cross functional teams which most managers hate.

Re: How Equifax Was Breached in 2017

#67
post #32

Not mentioned here was that the group that exploited the vulnerability handed over to PLA linked individuals who then conducted the exfiltration. https://www.justice.gov/opa/pr/chinese-military-personnel-ch... As far as I am aware the data has never been seen on the open market, so there's a whole other National Security story around whether the information was used to compromise individuals with credit issues for co…

Just curious how can I check whether a data set is on market?

Re: How Equifax Was Breached in 2017

#68
post #60
post #41

Earlier quoted context omitted.

Also mis-mentioned, is that I heard nothing was "missed" but security upgrades were not possible due to the age of the stack. Pre-0 days are one thing. But leaving systems unpatched for months, because your stack is too old, is a common, but inexcusable theme. This is why it is vital to use libraries, frameworks, with a stable, unchanging LTS branch. Failure to do so, means a security update that needs to be applied…

Been a few years since I read it, but worth a look due to the detail it goes into. https://www.hsgac.senate.gov/wp-content/uploads/imo/media/do...

"They routed traffic through approximately 34 servers located in nearly 20 countries to obfuscate their true location, used encrypted communication channels within Equifax’s network to blend in with normal network activity, and deleted compressed files and wiped log files on a daily basis in an effort to eliminate records of their activity."

I wonder how they managed to figure that out. Did they have to look into each of the servers?

How did they get the names?

Re: How Equifax Was Breached in 2017

#69
This is a nice list of could've, should've, would've's. But you'd have to dig deeper to get to the core.

Why did these things happen (or not happen)? Insufficient training? Insufficient processes? Were changes being reviewed and accepted by people who didn't really understand the changes, for expediency? Were there alerts but they were lost in the noise of thousands of bogus alerts people had learned to ignore? Was the lack of segmentation a known issue but allowed because it made some things easier? Were the credentials stored on NFS because they simply hadn't setup a more appropriate system yet and that was considered low-priority? Were business priorities getting in the way of technical priorities such that known issues were backlogged?

It's fairly easy to make a bullet list of things that should (or shouldn't) be done. It's a bit more difficult to figure out why, in a specific organization, those things aren't (or are) being done. Even if/when people might know that they should/shouldn't.

The surface level mistakes are interesting. The deeper organizational causes of those mistakes would be interesting. Solving those things at a higher systemic/organizational level can reduce the whack-a-mole nature of individual mistakes.

Re: How Equifax Was Breached in 2017

#70
post #55
post #28

Earlier quoted context omitted.

Yes, this is what most people don't understand with data breaches: it's not the company's data, it's data on others. That's why they don't really care about protecting it.

Come on man ... no company wants their DB leaked regardless of what's inside. There's probably zero Western companies in 2023 that "don't care" about PPI leaking from their systems.

People care about events when the outcomes of those events have consequences either for the company or better still those in charge of the company.

The reality is that despite Equifax showing a blatant disregard for the security of the data they have on people, the repercussions of this breach were trivial to them and their senior people.

So yes, I do agree that there is at least one company out there, Equifax, who does not care about PPI leaking from their systems.

Post reply on HN