Live data from Hacker News

Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

gizmodo.com

31–40 of 99 posts

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#31
post #26
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…

That is shameful incompetence. Disgraceful.

In a followup this person makes some excuse about how many emails they get because they're a big company. Why even have the email address then, if you're just going to disregard everything right off the bat? The initial email was rather specific with regard to the issue, but even if it wasn't, send them the fucking PGP key and see what they send! If it's nothing worthwhile, oh well, no big deal.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#32
post #26
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…

reminds me of the time Oklahoma City was threatening CentoOS with calling the FBI because there website was down and they thought CentOS hacked it:

https://www.theregister.co.uk/2006/03/24/tuttle_centos/

If you are in a position where you don't understand the e-mail then ASK someone who does. Or a quick google search with "PGP e-mail", wow was that so hard. The guy was probably late for a golf game or something (ok now i am being mean). Idiots.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#33
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.

it's who you know ...

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#34
post #26
post #6

I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…

The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…

It's shocking how far up you can make it in enterprise environments on pure bluster alone.

Perhaps a contributing factor to the Peter Principle?

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#36

Earlier quoted context omitted.

How do people so dangerously incompetent get hired into these roles? Edit: My question and the replies are incredibly depressing as an infosec practitioner.

"Experience"

and connections, knows someone who knows someone

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#37

Anyone have a current status on how to effectively sue Equifax for data exposed?

Last year, I tried to sue them in Small Claims court (in California) using this as a guide: https://blog.legalist.com/i-won-8-000-from-equifax-in-small-... .

For me, it was unsuccessful. They sent out a representative and we argued away from a judge (forget the term used) and I decided not to see the judge because if I argued before him and lost, I would be "unable" to bring it before a judge again.

I've heard of this tactic working for certain consumers (like in the article above) but for me what was hard to establish via small claims court, was how exactly I was facing monetary damages. Most lawsuits allow punitive damages, but small claims court does not, so you have to prove exactly how you were monetarily damaged.

That being said, I would definitely be down to sue them in small claims court again using a better strategy. I would also join a class action lawsuit.

Re: Moody’s downgraded Equifax from “stable” to “negative” due to cybersecurity

#38
post #2

> Moody’s downgraded Equifax from a “stable” to a “negative” outlook > Lawsuits and investigations have cost $690 million in the first quarter of 2019 alone > And the lawsuits will keep coming: In January, an Atlanta judge denied Equifax’s attempts to dismiss class-actions filed against the company. Looks like there are real consequences to losing data on half of all Americans

But not because of anything Congress did.

I don't think it's necessarily a bad thing that existing laws and civil structures are capable of dealing with this without new laws having to be passed explicitly for this case.

Doing it more quickly would have been nice, sure.

Post reply on HN