Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and p…
Hackers who broke into Equifax exploited a flaw in open-source server software
31–40 of 84 posts
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#32Earlier quoted context omitted.
So if someone takes this data and just keeps the whole dataset exposed publicly on a tor site, is that pretty much the end of data breaches? Like, some random website: "we just got hacked, all you pii was taken, but don't worry nothing thats not already available in that public database" other than new credit card #'s it'd be basically pointless right?
Well... no. Everybody on that list will change their CC and life carries on until the next breach.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#33Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and p…
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#34Earlier quoted context omitted.
If it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and p…
There are many networks where having a raspi on the network gives you no particular advantage.
Most devs have creds littered throughout their system. Some subset of the creds will get me access to your network. If you let me rifle through your box for a few hours I'd likely find a way to pivot somewhere else.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#35Earlier quoted context omitted.
Sure, if you don't have physical security, you have no security. Goes without saying.
Unfortunately ~nobody does. The effectiveness of red teams was one of the most surprising aspects of working in security. The most common way to break into someplace was to pose as a construction worker: http://i.imgur.com/ZjnGmZ5.png If you're dressed as one of them, you can go wherever you want and people rarely ask questions. Another approach is to pose as an interviewee. That's how you get into the building, but…
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#36Earlier quoted context omitted.
> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.
Which way to the frog sauna?
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#37Earlier quoted context omitted.
Which way to the frog sauna?
I have to be honest, I have no idea what you mean. I tried googling "frog sauna" but all I got were advertisements for actual saunas for frogs. Lol ️
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#38Earlier quoted context omitted.
Unfortunately ~nobody does. The effectiveness of red teams was one of the most surprising aspects of working in security. The most common way to break into someplace was to pose as a construction worker: http://i.imgur.com/ZjnGmZ5.png If you're dressed as one of them, you can go wherever you want and people rarely ask questions. Another approach is to pose as an interviewee. That's how you get into the building, but…
So, every time, he took a pic in the exec's chair, stole a file from the server room, and also did whatever he wanted? What is the 'N' factor here, because it sounds like your friend is a bold high schooler who achieved N=1,2,3(tops). Pretty boring security stuff.
These gigs are highly paid and secretive. The coworker I mentioned went on dozens of assignments like this. Admittedly he was legendary, but only because he was so experienced. If you were motivated and malicious, you could do many of the same things to attack a target network. People rarely do that, but it's the ultimate proof that none of us are secure against motivated adversaries.
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#39Earlier quoted context omitted.
Unfortunately ~nobody does. The effectiveness of red teams was one of the most surprising aspects of working in security. The most common way to break into someplace was to pose as a construction worker: http://i.imgur.com/ZjnGmZ5.png If you're dressed as one of them, you can go wherever you want and people rarely ask questions. Another approach is to pose as an interviewee. That's how you get into the building, but…
So, every time, he took a pic in the exec's chair, stole a file from the server room, and also did whatever he wanted? What is the 'N' factor here, because it sounds like your friend is a bold high schooler who achieved N=1,2,3(tops). Pretty boring security stuff.
Side note, that sounds like something one of my old bosses would do on his red team excursions (he also told me to get my teeth pulled without anesthetics at all, so... yea).
Re: Hackers who broke into Equifax exploited a flaw in open-source server software
#40Credit card companies could provide other businesses such as Equifax distinct mere-reference numbers which the customer doesn't see and which can't be used for purchases - just to absolutely identify which card, for all parties. These could be added to the magnetic stripe or chip in the card, for example. (It might be gilding the Lilly, but many such reference numbers could be used for a given card, re privacy issues or otherwise. But then those numbers couldn't be usefully passed between companies for all purposes.) There's no need for anyone but the customer and Credit Card company itself to retain the actual credit-obtaining-number (other than to allow future purchases with permission, which is the rarer case, often needs to be prevented not facilitated, and doesn't excuse Equifax having more than a reference number.) Yet the credit card companies don't do this. Why not? 'Cause humans are idiots, all of us, that's why. PS - run to the patent office and you might be able to make a ton of money patenting this, since patents are now given to whoever shows up at the patent office with the appropriate fees first. Precedence doesn't matter. You would be implying that you thought the idea up independently, of course, but you're smart, right? That's totally the sort of thing you could think of independently. Then when you're rich, you too can help choose what the patent laws look like, and whether rich people should pay taxes.