Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

151–160 of 227 posts

Re: Equifax securities fraud class action [pdf]

#151
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Another approach would be to start fining organizations that leak personal information. If the fine was sufficiently large per individual companies would then be incentivised to start taking security seriously and third party audits would probably be part of that.

Re: Equifax securities fraud class action [pdf]

#152

Earlier quoted context omitted.

From the parent: > These sales were not made pursuant to a Rule 10b5–1 trading plan.

"pre-arranged" != "Rue 10b5-1 trading plan" I'm not an expert in stock trading, but this logic seems very plausible. A Plan does not preclude other arrangements to sell shares

Maybe, but "pre-arranged legally" == "Rue 10b5-1 trading plan".

So if it was pre-arranged but was not following the rules, it doesn't matter that it was pre-arranged, it's still counts as illegal insider trading as-if not pre-arranged.

Reasons being super obvious, since it would be easy to do insider trading in a stealthy way otherwise.

Re: Equifax securities fraud class action [pdf]

#153
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

I was once pulled in to consult on a new unix system that was being connected to a bank's mainframe. The operator I was working with, who had worked on mainframes his entire career, hesitated and said he needed to call someone because he couldn't remember the password into the unix system. When they didn't answer, I asked if they wanted to try 'root', or something. They did. It worked. Stunned silence followed. They wanted to know how I knew that. Nobody was supposed to know that.

Re: Equifax securities fraud class action [pdf]

#154

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

I'm confused why they didn't get prosecuted (at least not yet). The CIO actually got fined and sent to prison for insider trading: https://www.justice.gov/usao-ndga/pr/former-equifax-employee...

Scapegoat?

Re: Equifax securities fraud class action [pdf]

#155

Earlier quoted context omitted.

Yup. According to formal logic, the answer then is just yes. p or true => true

In natural language, "or" generally means "xor" - as is the case here.

Obviously you're probably right, but I'll just try to troll this a bit. According to the principle of charity (or steelmanning), you should interpret an argument in the strongest possible way, and thus you should in this case interpret the statement with an inclusive or, which is more likely to be true.

Re: Equifax securities fraud class action [pdf]

#156

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

It's sad how obvious this is. Possibly even more obvious than the insider trading at intel prior to the spectre/meltdown public release. This will be forever the legacy of Eric Holder, the man who changed the justice department policy to go after smaller 'fines' as settlements instead of prosecuting crimes.. only because of the simple fact that fines are easy to win, and criminal cases can be lost. Justice is now esc…

Correct me if I'm wrong, but isn't it the job of the SEC to investigate the insider trading, and then call in the DOJ if they deem it necessary to file criminal charges?

Re: Equifax securities fraud class action [pdf]

#157

Earlier quoted context omitted.

"What's the frequency, Kenneth?" https://en.wikipedia.org/wiki/What%27s_the_Frequency,_Kennet...

Alternative reference is Spaceballs: Dark Helmet's locker combination.

Except this one was at least a 6 digit pass code rather than the four digit 1234 from Spaceballs. At least give them that credit?

Re: Equifax securities fraud class action [pdf]

#158
post #145

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

It's possible they were already planning to make those sales. Executives who can potentially have inside information often need to tell the SEC far ahead of time about sales they intend to make.

"These sales were not made pursuant to a Rule 10b5–1 trading plan" They didn't report in advance.

Re: Equifax securities fraud class action [pdf]

#159
post #150

Is there some nuance to this admin/admin used to access a portal? I can completely imagine a headline like this when there is an old basic auth overlaying an application with a real password. It just seems unlikely that all the logging in the customer service portal will say, "updated by admin".

Could be something like the trivial portal login was protected by VPN.

Re: Equifax securities fraud class action [pdf]

#160
post #60

Earlier quoted context omitted.

There could be whistleblower protections for hackers. Consider the previous attitude was hackers are causing millions of dollars of damage and need to be thrown in prison. With the proliferation of state sponsored and counter intelligence hacking over the past 15 years, no one believes you can make anything secure just by throwing enough teenage script kiddies in federal prison. The reverse now is companies are takin…

While nothing is impervious that really has nothing to do with Equifax. Equifax is a case of gross negligence and malfeasance. There were no less than three security audits of Equifax going back as early as 2014. Every audit indicated major security vulnerabilities and Smith disregarded these audits each time.

Who was paying for the security reviews if they were just going to be ignored? Some management or regulatory process?
Post reply on HN