Live data from Hacker News

Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

bloomberg.com

21–30 of 80 posts

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#22
post #21

If they had an outside security firm helping them starting in March, and another breach in July, that doesn't say much for the capabilities and competency of the security firm.

It's quite possible the security firm was asked to audit their systems, but not asked (or paid) to fix them.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#23
post #19

> One possible explanation, according to several veteran security experts consulted by Bloomberg, is that the investigation didn’t uncover evidence that data was accessed. Most data breach disclosure laws kick in only once there’s evidence that sensitive personal identifying information like social security numbers and birth dates have been taken. There was one company (very well known) I know of that was breached, b…

Between this and them lobbying for no-fault for data exfiltration, it keeps getting better and better. My credit has been locked since the OPM fiasco, I'd like to recommend others consider it.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#24
post #22
post #21

If they had an outside security firm helping them starting in March, and another breach in July, that doesn't say much for the capabilities and competency of the security firm.

It's quite possible the security firm was asked to audit their systems, but not asked (or paid) to fix them.

A lot of people want you to come in and find a quick answer and fix, rarely allowing a full proper investigation. Many times they're adverse to spending money and want to cut corners where they can. It's actually disheartening. Much like one of the posters above, I've seen people purposely stop investigations because if the investigation reported on known issues it would open up more questions about other wrong doings.

The Irony is their actions on remediation are almost exactly in line with the decisions made that often times lead to the incident. It's cyclical.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#25
post #16
post #7

I think it's good news- if your identity has not been used, there's less chance that it will be, because the data has been already out for that long.

To red team that line of reasoning: hold on to the hacked data but don't use it, wait till public forgets about it, don't give business/lawmakers a reason to neuter the data, then strike a few years down the line.

Username related; please don't.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#26
post #19

> One possible explanation, according to several veteran security experts consulted by Bloomberg, is that the investigation didn’t uncover evidence that data was accessed. Most data breach disclosure laws kick in only once there’s evidence that sensitive personal identifying information like social security numbers and birth dates have been taken. There was one company (very well known) I know of that was breached, b…

I worked on a breach where during the investigation we found reverse tunnels out of the network (back to the VP's house) where he'd been working on stuff unbeknownst to the firm. They had a VPN to a competitor that a sales engineer had setup when they were exploring collaboration, that had never been closed. Their DMZ was awesome on paper (cool color chart) but was literally non-existent. The final icing on the cake, their network equipment and firewalls were all second hand with existing firewall rules left when new ones were added. After printing out the rules.. at the very bottom ANY/ANY. There wasn't a lack of money, hundreds of millions were dumped in by investors. Everyone there had the i'm an engineer so I don't have to follow rules, that's for the sales guys attitude and that more than did them in from a security perspective.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#27
post #12
post #10

Earlier quoted context omitted.

I was told they usually aren't used until at least a year after the fact, because this line of reasoning. Not sure how true that is.

I would probably wait at least until everybody's free fraud protection expires, which is usually a year.

This is exactly how it works. Passwords can be changed, your personal details can't.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#28
post #21

If they had an outside security firm helping them starting in March, and another breach in July, that doesn't say much for the capabilities and competency of the security firm.

I am not sure about origins, but the name they disclosed in their PR is of a very capable outfit.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#29
post #18

IMPORTANT: The date of disclosure is ALSO the date that demand for hacked data explodes. It's good practice to have a staged-disclosure procedure for leaks of this nature. For example: your bank should be told to start fine-tuning its anti-fraud capabilities BEFORE the entire world is made aware that you can be defrauded in this particular manner.

I noticed that too. If they released breach information before trying to patch it up, that would have been a horrible play.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#30
post #19

> One possible explanation, according to several veteran security experts consulted by Bloomberg, is that the investigation didn’t uncover evidence that data was accessed. Most data breach disclosure laws kick in only once there’s evidence that sensitive personal identifying information like social security numbers and birth dates have been taken. There was one company (very well known) I know of that was breached, b…

Sure, that combined with the fact that courts simply refuse to refer to anything involving software a 'negligence', no matter how extravagantly negligent it might be, would make that a pretty good strategy. The only flaw in it, really, is that it would also open you up to things like the Sony hack which actually had them shut down operations for awhile. As much as companies REALLY do not want to ever admit it, no matter what they do, their software IS their business in every sense. Without it in a working state, they have to shut their doors. So I suppose you have to strike a balance... secure enough that things keep working, but not so secure that it actually costs money...
Post reply on HN