Live data from Hacker News

How Equifax Was Breached in 2017

blog.0x7d0.dev

1–10 of 117 posts

Re: How Equifax Was Breached in 2017

#4
post #2

If any company deserves the corporate death penalty, it's Equifax after this fiasco. That company should no longer exist.

Ok, but please don't post generic comments, and especially not generic-indignant comments, to HN. They lead to significantly less interesting discussion.

Re: How Equifax Was Breached in 2017

#5
TLDR is:

Equifax had no working firewall / intrusion detection for almost a year, because they did not update their snakeoil MITM certificate and forgot about it.

Remind me again, how did Equifax get SOC 1&2, and ISO27001 certified?

Oh yeah, they probably have a checklist for that, so they must be secure. /s

Re: How Equifax Was Breached in 2017

#8
> Malicious actors had been exfiltrating data for several months and had already collected personal information from 163 million customers.

I don't think "customers" is the right term, considering I never wanted them collecting data about me.

Post reply on HN