Live data from Hacker News

JPMorgan Discovers Further Cyber Security Issues

dealbook.nytimes.com

1–10 of 20 posts

Re: JPMorgan Discovers Further Cyber Security Issues

#4
post #3

"In the filing, JPMorgan said there was no evidence that account information, including passwords or Social Security numbers, were taken." I wonder what was actually "compromised" about the 76 million accounts if not account information.

Read the filing:

User contact information – name, address, phone number and email address – and internal JPMorgan Chase information relating to such users have been compromised.

The compromised data impacts approximately 76 million households and 7 million small businesses.

However, there is no evidence that account information for such affected customers – account numbers, passwords, user IDs, dates of birth or Social Security numbers – was compromised during this attack.

http://www.sec.gov/Archives/edgar/data/19617/000119312514362...

Re: JPMorgan Discovers Further Cyber Security Issues

#5
Is anyone really surprised?

IT Security is a cost center and, honestly, the damage from this hack (money wise) to JP Morgan is likely less than the cost of better security.

Also, the larger the payoff ... the more effort people will put into the attack. No IT system is 100% secure unless its been shredded. Even a no-network PC in a vault is still vulnerable to a vault door breach.

Re: JPMorgan Discovers Further Cyber Security Issues

#6
post #4
post #3

"In the filing, JPMorgan said there was no evidence that account information, including passwords or Social Security numbers, were taken." I wonder what was actually "compromised" about the 76 million accounts if not account information.

Read the filing: User contact information – name, address, phone number and email address – and internal JPMorgan Chase information relating to such users have been compromised. The compromised data impacts approximately 76 million households and 7 million small businesses. However, there is no evidence that account information for such affected customers – account numbers, passwords, user IDs, dates of birth or Soci…

"However, there is no evidence that account information for such affected customers – account numbers, passwords, user IDs, dates of birth or Social Security numbers – was compromised during this attack."

Perhaps someone who has more experience with security and system administration can answer this: If you get root access to a system (as mentioned in the original article), isn't it fairly easy to make it nearly impossible to find evidence that any particular piece of information has been compromised?

It's funny that this wording (there is no evidence) should be used. I don't know if JPMorgan can confidently assert that this information has not been compromised, yet when stated this way it sounds like they are.

Re: JPMorgan Discovers Further Cyber Security Issues

#7
post #6
post #4

Earlier quoted context omitted.

Read the filing: User contact information – name, address, phone number and email address – and internal JPMorgan Chase information relating to such users have been compromised. The compromised data impacts approximately 76 million households and 7 million small businesses. However, there is no evidence that account information for such affected customers – account numbers, passwords, user IDs, dates of birth or Soci…

"However, there is no evidence that account information for such affected customers – account numbers, passwords, user IDs, dates of birth or Social Security numbers – was compromised during this attack." Perhaps someone who has more experience with security and system administration can answer this: If you get root access to a system (as mentioned in the original article), isn't it fairly easy to make it nearly impo…

> isn't it fairly easy to make it nearly impossible to find evidence that any particular piece of information has been compromised?

This is where digital forensics comes in. Just because an attacker has root or admin access doesn't mean all indicators of a compromise can be cleaned up.

Re: JPMorgan Discovers Further Cyber Security Issues

#8
post #6
post #4

Earlier quoted context omitted.

Read the filing: User contact information – name, address, phone number and email address – and internal JPMorgan Chase information relating to such users have been compromised. The compromised data impacts approximately 76 million households and 7 million small businesses. However, there is no evidence that account information for such affected customers – account numbers, passwords, user IDs, dates of birth or Soci…

"However, there is no evidence that account information for such affected customers – account numbers, passwords, user IDs, dates of birth or Social Security numbers – was compromised during this attack." Perhaps someone who has more experience with security and system administration can answer this: If you get root access to a system (as mentioned in the original article), isn't it fairly easy to make it nearly impo…

A business like JPMorgan will have a large number of systems, with different segments of their data copied around, synchronized (sometimes poorly), partial data dumps to the marketing department, etc. I imagine that the systems containing sensitive data were better protected than the ones that are known to be compromised, with no known vector of attack from the compromised system to the one containing the information.

For example, at a small financial institution where I worked we had a mainframe doing the important financial calculations, and then we had a bunch more data in MySQL for doing reporting and analysis.

Re: JPMorgan Discovers Further Cyber Security Issues

#10

This is interesting: "made off with a list of the applications and programs that run on every standard JPMorgan computer". That would mean source codes of the applications?

I would not infer that the "list of the applications and programs" would mean the "source code of the applications".

I would assume its literally what it says, the lists most big orgs maintain of their standard system configuration(s).

Post reply on HN