Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

201–210 of 227 posts

Re: Equifax securities fraud class action [pdf]

#201
post #90
post #82

Earlier quoted context omitted.

There are two types of possible regulation, one is control and the other is liability. With control, some administrative body says you have to do X, Y and Z. And presumably, if you jump through the hoops and it blows up, there is an implicit guarantee. This kind of regulation is common across banks, and in 2008 when all the reserve requirements were deemed insufficient and all the acceptable ratings meaningless, ther…

I don't see much difference in the two approaches, except the later case will require customers to collectively sue you for damages, in which case you can probably run a cost-benefit analysis to find out if it would be worth it. In a regulatory environment, if a corporation does not comply, the punishment is increased until either the corporation complies or seizes to exist. Since not existing is bad for profit, corp…

The difference is pretty big because there are a couple of conflicting things with the regulatory regime: it must be predictable (if things change rapidly, it becomes hard to comply and you'll get defacto non-compliance and shadow data storage) and it must be up to date. Policy makers usually don't specifically want punishments or changes in behaviour, they want outcomes.

In a liability environment, you attempt to describe the true cost and risk and allow the company to adapt to changing environments.

A practical real-world difference is "password rotation requirements". Most real-world security professionals knew the dangers of strict password rotation requirements for years before NIST could release information on it. And just because the process of standardization must necessarily be slow, the NIST requirements would then have to flow to other departments so they can then update their standards and so on.

Today, in most financial and healthcare companies, password rotation standards are rampant despite it being the case that NIST has advised against. This is often because the companies don't want to spend the money to alter policies but also often because in the 'no-man-is-an-island' interconnectedness of firms, policies in one can impose corresponding policies in others. So that means that your new startup will need to rotate passwords every month in order to integrate with (say) Bank of America.

Apart from all that, if you genuinely think about it, we want to do cost-benefit analyses on this. If the risk of leakage of customer data is low enough and we value it at some $x dollars per unit, then there's some $y of cost above which it isn't worth it. This intuitively makes sense since customer data, no matter how personal, isn't worth infinity. If it were, no one would collect it. No one. In fact, by giving me your phone number I would suddenly be holding an artefact of infinite value. Or by giving Amazon your shipping address. No one wants that liability and information exchange would halt despite everyone (in reality) wanting it to happen.

Re: Equifax securities fraud class action [pdf]

#202
post #90

Earlier quoted context omitted.

I don't see much difference in the two approaches, except the later case will require customers to collectively sue you for damages, in which case you can probably run a cost-benefit analysis to find out if it would be worth it. In a regulatory environment, if a corporation does not comply, the punishment is increased until either the corporation complies or seizes to exist. Since not existing is bad for profit, corp…

The difference is pretty big because there are a couple of conflicting things with the regulatory regime: it must be predictable (if things change rapidly, it becomes hard to comply and you'll get defacto non-compliance and shadow data storage) and it must be up to date. Policy makers usually don't specifically want punishments or changes in behaviour, they want outcomes. In a liability environment, you attempt to de…

Password Rotation and stagnant security practises are IMO a result of liablity environments, not regulatory environments.

Re: Equifax securities fraud class action [pdf]

#203
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

There are external financial audits to provide public information about a company's finances are accurately reported to the public. We need the same thing for security, because there's no real way of assessing that as an outsider and that knowledge is a public good, much like a corporation's finances.

Re: Equifax securities fraud class action [pdf]

#204
post #202

Earlier quoted context omitted.

The difference is pretty big because there are a couple of conflicting things with the regulatory regime: it must be predictable (if things change rapidly, it becomes hard to comply and you'll get defacto non-compliance and shadow data storage) and it must be up to date. Policy makers usually don't specifically want punishments or changes in behaviour, they want outcomes. In a liability environment, you attempt to de…

Password Rotation and stagnant security practises are IMO a result of liablity environments, not regulatory environments.

Interesting. I can see the rationale for that: we currently exist in a liability environment and that's where we are. The CYA process means that people stick to what's already there because introducing a change means you're on the hook for the change.

What I hoped for is that I, as a startup, can beat the government on picking a security standard because the government has to cater to all but I can just beat it by being better than Big Slow Dinosaur (BSD). But because I have to integrate at some level with BSD that has to follow the government I lose that advantage.

I suppose, with a regulator capable of moving fast to respond to threats, aware of sunset periods, regulation could be superior. Somehow, I expect forums like this one to be full of software engineers complaining about "the constantly changing requirements from NIST" if that were to happen.

Re: Equifax securities fraud class action [pdf]

#205

Earlier quoted context omitted.

I'm confused why they didn't get prosecuted (at least not yet). The CIO actually got fined and sent to prison for insider trading: https://www.justice.gov/usao-ndga/pr/former-equifax-employee...

Of course the IT guy goes down while the CFO runs out the back door with a fistful of dollars.

Calling a CIO “the IT guy” is ridiculous.

Re: Equifax securities fraud class action [pdf]

#207

Earlier quoted context omitted.

I'd like to defend Eric Holder. It's no secret what he does or who he works for. He's a lawyer that works for the big banks and other powerful industries, his job is literally to keep them out of legal trouble. We should be pointing the finger at the people who knew all these things and still put him in charge of the justice department. We should also be pointing the finger at the ones who have the power to change th…

Nah, doing that might actually prevent things like this from happen, so we should all downvote you instead.

Now we've got William Barr who has worked for Pillsbury and Kirkland & Ellis. You know, the exact same groups who represent scumbags like Epstein and BP...

https://en.wikipedia.org/wiki/Kirkland_%26_Ellis

Meanwhile, I'm some kind of "radical" for even pointing this out...

Re: Equifax securities fraud class action [pdf]

#208
post #205

Earlier quoted context omitted.

Of course the IT guy goes down while the CFO runs out the back door with a fistful of dollars.

Calling a CIO “the IT guy” is ridiculous.

As opposed to? The CIO is generally overseeing everything IT.

Re: Equifax securities fraud class action [pdf]

#209

Earlier quoted context omitted.

Arranging some other transaction (e.g. buying a yacht) in advance that would require cash, so the executive plans in advance a single sale to execute just ahead of the need for cash. If we go with the yacht purchase, perhaps in six months the builder needs final payment, so Mr. Executive arranges for a single sale of company stock a couple weeks before that date. Maybe such a thing does indeed require amending The Pl…

Not an expert either, but if such a thing was allowed, you could arrange to buy expensive stuff you want to have on a regular basis (I would assume this is not uncommon for CEOs) and then just agree orally with the seller to cancel the transactions when the stock is down, go through with it when the stock is up.

I think cancelling at opportune moments would fall afoul of 'pre-arrangment' whether using a plan or not.

Re: Equifax securities fraud class action [pdf]

#210
post #205

Earlier quoted context omitted.

Calling a CIO “the IT guy” is ridiculous.

As opposed to? The CIO is generally overseeing everything IT.

Probably as opposed to calling the CFO "the finance guy" in the same sentence as "the IT guy".
Post reply on HN