Live data from Hacker News

First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

krebsonsecurity.com

141–150 of 171 posts

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#141

Earlier quoted context omitted.

Of course I was being ironic about it being ”finely tuned”! What I’m saying is that in spite of having, in a sense, all the resources at their disposal, this process was chosen by the business, for the business. An encrypted on-line service could, and should, have been implemented. But being far from tech & dev the business choose a process matching their compentecies. Messing with this several years in, and trying t…

Right. I'm 'business' and the split 'business' vs 'tech' should not be there. I'm sure we've both seen terrible things, these are reinforced by organisational constructs. Escalate escalate escalate if you see something wrong. To coin a bigcorp slogan, of a company I admire the mission of, "Do the right thing" and "Not good enough." I recently opened a new bank account in the UK and chose a 'challenger' bank. The proc…

I for one am through escalating stuff in a hierarchical organization. Too much politics.

I’ve been out of that game for a few years and have no ambitions make a career for myself at such a place.

In a very big, top down org. ponder the following:

Granting, in a specific scenario, that I’m right — this “whatever” is a disaster waiting to happen or possibly an already flaming disaster, heads have to roll.

Someone always have to take the blame, as this most likely will affect someones budget or set goals.

It might have profound effects on the current “1.” or “.One” consolidation & synergetic tech project that management is giving misdirected focus at the moment.

The “1Whatever” projects usually have bizarre amounts of $$$ attached, and end up holy.

Have you worked big enough companies you know about the “whateverOne” projects I’m referring to!

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#142

A lot of discussion on technical side, but not from organisational. How could audit, both internal and external, not find this? 2003 to today is 16 years. Audit is a last line of defence and certainly not to be relied on upon as a buddy to catch your errors. But... how? This is a major financial institution in the most developed country in the world (the clue's in the name). It should subscribe to the the highest int…

You know what's a great incentive to actually care about this stuff? Legal consequences for not caring about it.

Anyone conceivably responsible for ignoring the developer's complaint should be on trial right now.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#143
post #84

Earlier quoted context omitted.

that is a good idea but most of the time I need to hand over my actual ID, and not just a scan of it

I'm usually an uncooperative bastard at times like this. I ask them what their purpose is in retaining a copy of my identity document, and I ask for their privacy policy. When I'm travelling for work and a hotel asks I simply say no, and remind them I can lodge a complaint with our corporate travel provider that will have them delisted for future business; usually they come to their senses. For overseas travel (where…

Where do they ask you for a copy of your ID? I've never had that happen to me at a hotel.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#144
post #17

At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already. The chickens will continue to come home to roost until people treat digital security as seriously as physical security.

I wonder if we should take mandatory breach reporting a step further too and require them to list all security vendor products and services that were in place at the time of the breach. Should security solution vendors be held to account for failing to live up to the bold claims they make?

That would be unfair, as the efficacy of most products depends on how they are configured, monitored and maintained.

For example, if I install an application whitelisting system, but whitelist too much, pay no attention to logs and alerts, or never patch it, then that's not really the vendor's fault.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#145

Earlier quoted context omitted.

Right. I'm 'business' and the split 'business' vs 'tech' should not be there. I'm sure we've both seen terrible things, these are reinforced by organisational constructs. Escalate escalate escalate if you see something wrong. To coin a bigcorp slogan, of a company I admire the mission of, "Do the right thing" and "Not good enough." I recently opened a new bank account in the UK and chose a 'challenger' bank. The proc…

I for one am through escalating stuff in a hierarchical organization. Too much politics. I’ve been out of that game for a few years and have no ambitions make a career for myself at such a place. In a very big, top down org. ponder the following: Granting, in a specific scenario, that I’m right — this “whatever” is a disaster waiting to happen or possibly an already flaming disaster, heads have to roll. Someone alway…

Yup, raise any flags and risk being treated as an outsider/treated poorly. That's my current situation after raising concerns ranging from being way overcharged on a government client project by a vendor who happens to be friends with a manager, and catching a now ex manager pulling mitm attacks on a router (to snoop/play politics) which happens to be on the same network as servers housing client data. It's an awful feeling not being able to have glaring issues resolved or be treated like shit after doing what seemed right and in the best interest of the company.

Needless to say, I'm making moves to get the hell out of there

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#146
post #83

Earlier quoted context omitted.

I also don't think using UUIDs as a security (by obscurity) strategy is valid. But there are other reasons someone may choose to use UUIDs. For instance, it's convenient to generate identifiers in a decentralized manner. I want to counter your one bad experience with my (equally anecdotal) many-multiple good experiences. Databases do just fine with UUIDs. Though we may be working on different kinds of systems, and op…

> For instance, it's convenient to generate identifiers in a decentralized manner. For an elegant solution to this problem, check out Twitter's Snowflake[0]. [0] https://blog.twitter.com/engineering/en_us/a/2010/announcing...

I always wondered why databases have not implemented a scheme like Microsoft's Active Directory RID master FSMO role. One server is responsible for handing out chunks of ID's to each server. They request a new block whenever a threshold is reached (50% by default IIRC).

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#147
Programmers fault? Audits fault? Securities fault? Pentesters fault? It fault?

Listen until C-level funds these programs properly and security is taken seriously by all issues like this will forever be in the news.

I would be willing to bet their security like most have a long list of security gaps they cant get fixed because resource issues just hope they documented or it could fall on them.

Most coding classes just teach how to make things work in Mister Roger's world. Secure coding is an elective! Most run the DevOps model instead SecDevOps and only involve security after it is ready to go into production no matter what flaws security finds.

Why are black box pentests still taking place? Because company required to have pentest but really do not want testers to find things. Their goal is not to improve security rather check that box ... we had a pentest.

C-level, this keep the lights on budget you give Security/IT is costing you more than properly funding us! Oh yeah you put that $ into cyber insurance! Lol let's see how well that works.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#148

Earlier quoted context omitted.

Right. I'm 'business' and the split 'business' vs 'tech' should not be there. I'm sure we've both seen terrible things, these are reinforced by organisational constructs. Escalate escalate escalate if you see something wrong. To coin a bigcorp slogan, of a company I admire the mission of, "Do the right thing" and "Not good enough." I recently opened a new bank account in the UK and chose a 'challenger' bank. The proc…

I for one am through escalating stuff in a hierarchical organization. Too much politics. I’ve been out of that game for a few years and have no ambitions make a career for myself at such a place. In a very big, top down org. ponder the following: Granting, in a specific scenario, that I’m right — this “whatever” is a disaster waiting to happen or possibly an already flaming disaster, heads have to roll. Someone alway…

I don't know what 1.whatever is. Yes, I've worked for supercorps, mainly financials, and I have a responsibility to ensure customer and employee data are managed responsibly.

It is important to escalate what doesn't seem right. Sometimes that means email after email after email (written record) and that if it still doesn't smell right to keep pushing. Ops was a strange place, but 500 emails per day is no longer a challenge.

I commented this as an organisational failing rather than a technical one as a debate about UUIDs seems to be missing the point that people could have been aware something was not right but did not, or weren't allowed, or it got drowned in organisation, to do anything.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#149

A lot of discussion on technical side, but not from organisational. How could audit, both internal and external, not find this? 2003 to today is 16 years. Audit is a last line of defence and certainly not to be relied on upon as a buddy to catch your errors. But... how? This is a major financial institution in the most developed country in the world (the clue's in the name). It should subscribe to the the highest int…

You know what's a great incentive to actually care about this stuff? Legal consequences for not caring about it. Anyone conceivably responsible for ignoring the developer's complaint should be on trial right now.

I personally think the board and CEO should be personally criminally liable. I don't know exactly how but if I can't use ignorance of the law as a defense for shouting in public (one yell back at someone who yelled "fuck you" at me and I got a $180 fine) then the CEO and board can't use that as a defense for leaking data for SIXTEEN years.

Didn't know this was happening in your organization? Fuxk you, go to prison.

Re: First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

#150

Earlier quoted context omitted.

I for one am through escalating stuff in a hierarchical organization. Too much politics. I’ve been out of that game for a few years and have no ambitions make a career for myself at such a place. In a very big, top down org. ponder the following: Granting, in a specific scenario, that I’m right — this “whatever” is a disaster waiting to happen or possibly an already flaming disaster, heads have to roll. Someone alway…

I don't know what 1.whatever is. Yes, I've worked for supercorps, mainly financials, and I have a responsibility to ensure customer and employee data are managed responsibly. It is important to escalate what doesn't seem right. Sometimes that means email after email after email (written record) and that if it still doesn't smell right to keep pushing. Ops was a strange place, but 500 emails per day is no longer a cha…

Clarification on 1/one — in my experience big co is naturally striving for synergies and often target “IT” as it’s seemingly an obvious candidate.

These projects often bare a description such as “ProgramOne”, “Platform1” or 1SomethingAwesome, and is of a “bite of more than you can chew” character.

At least at three of class leading companies I’ve worked, all with 90.000+ employees.

It’s just my disillusionment shining through! :)

I believe we agree — the future holds a merger of tech with business and what I’ve stated above are org failures. That’s true.

IT must not block business, it should expose opportunities and be inherently secure by convention.

Post reply on HN