Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

1–10 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#2
"we did nothing"

Who?

These companies get sued, that is a reaction.

Congress? Well if you make a law twice as illegal, I'm sure that will make it stop /s.

No one wants to be hacked, let's not pretend there is no fallout from ignoring security.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#3
I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck?

For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming only a school.

Can the punishment for crimes stop being absurd. I am only reserving further outrage because those are the current charges against the hacker. We know more can pile up as they learn more.

Really though if that kind of PII can give you access to ruin someones financial life then it should be made harder to get credit cards. If you dont have a drivers license and other things to show you shouldnt get a credit card.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#4

"we did nothing" Who? These companies get sued, that is a reaction. Congress? Well if you make a law twice as illegal, I'm sure that will make it stop /s. No one wants to be hacked, let's not pretend there is no fallout from ignoring security.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years?

No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data secure and they didn't do enough.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#5

"we did nothing" Who? These companies get sued, that is a reaction. Congress? Well if you make a law twice as illegal, I'm sure that will make it stop /s. No one wants to be hacked, let's not pretend there is no fallout from ignoring security.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…

After 14 days it should be encrypted independent of any AWS encryption as someone mentioned in the other Capital One thread and the key should not be stored on a S3 container or some obvious service that can be easily compromised.

Keeping all your eggs in one basket (the cloud) is never a good idea. If you have to do it try and give yourself as much control over sensitive data via encryption of no longer to be accessed data.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#6

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

Prosecutor discretion exists. Furthermore, AFAIK (IANAL, especially not a US criminal justice lawyer), US sentencing guidelines take into account first-party financial damages (low for CapitalOne) not diffuse third-party damages of the kind suffered that will be suffered by the 100M people whose PII was lost.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#7

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

> If you dont have a drivers license and other things to show you shouldnt get a credit card.

In Europe everyone has to possess a personal ID card or a proper passport, and it is required to be presented to the bank agent (or a verification service). Yes, we do have some problems with faked ID cards and lately by fraudulent video identification, but still - not remotely comparable to the laughable "security" in the US.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#8
Wasn't this a private S3 bucket and she somehow hacked permission access? Anyone know the full details of how this came to happen?

As for mitigation, does S3 encryption happen at the user access level (GET) or S3 system level. Basically, does each GET call pass in the decryption key? This means an attacker needs another piece of information. More encryption wouldn't hurt here. This goes for Equifax too.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#9

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

> If you dont have a drivers license and other things to show you shouldnt get a credit card. In Europe everyone has to possess a personal ID card or a proper passport, and it is required to be presented to the bank agent (or a verification service). Yes, we do have some problems with faked ID cards and lately by fraudulent video identification, but still - not remotely comparable to the laughable "security" in the U…

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#10

"we did nothing" Who? These companies get sued, that is a reaction. Congress? Well if you make a law twice as illegal, I'm sure that will make it stop /s. No one wants to be hacked, let's not pretend there is no fallout from ignoring security.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…

Utopia solutions aren't really helpful for ideas.

It's great if companies had unlimited resources to spend on security, and didn't screw their customers with fees.

Let me remind you, even Apple had their phone hacked. More laws won't make mistakes go away.

Post reply on HN