Live data from Hacker News

Capital One’s breach was inevitable, because we did nothing after Equifax

techcrunch.com

31–40 of 161 posts

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#31
post #6

I said this on the other HN thread about CapitalOne but I found it ridiculous that Aaron Swartz was facing a hefty sentence and the culprit behind this hack last I checked is facing up to 5 years??? What the heck? For every person exposed in this hack is a single victim to be added. Not to mention the numerous indirectly affected people part of small businesses. Aaron Swartz hacked some ebooks by comparison harming o…

Prosecutor discretion exists. Furthermore, AFAIK (IANAL, especially not a US criminal justice lawyer), US sentencing guidelines take into account first-party financial damages (low for CapitalOne) not diffuse third-party damages of the kind suffered that will be suffered by the 100M people whose PII was lost.

CapitalOne disclosed that this hack is going to cost them between $100mm and $150mm, which is a lot more than JSTOR would have lost from Aaron Swartz's "hack" of academic humanities papers.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#32

Earlier quoted context omitted.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…

This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?

The OP called out "negligence," which would leave some wiggle room for the executive in your scenario. Promoting and spending directly on security would be proof that you're at least making a conscientious effort.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#33
post #6

Earlier quoted context omitted.

Prosecutor discretion exists. Furthermore, AFAIK (IANAL, especially not a US criminal justice lawyer), US sentencing guidelines take into account first-party financial damages (low for CapitalOne) not diffuse third-party damages of the kind suffered that will be suffered by the 100M people whose PII was lost.

CapitalOne disclosed that this hack is going to cost them between $100mm and $150mm, which is a lot more than JSTOR would have lost from Aaron Swartz's "hack" of academic humanities papers.

Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked.

If they had fallen victim to some undisclosed zero-day, I’d feel bad for them - but in this case it appears to be misconfigured VPC SGs. Their error. Inadequate processes.

We are also all labouring under the assumption that she was the only person to make off with this data.

I’m willing to bet that she’s just the first one daft enough to talk about it.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#34

Earlier quoted context omitted.

But your identity is verified through some means when opening an account, even if there is no unique document, no? Example https://www.tsb.co.uk/current-accounts/faqs/identity/

Yes it is. Electoral roll.

For which to get on you need an address to live at. For which to get one, you need a bank account (at least, but in 99.9% cases this alone is not enough), otherwise no agency is going to give rent you a house.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#35

Earlier quoted context omitted.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…

This line of thinking doesn't work. I want to agree with you, but I can't. An executive could do all the right things by promoting and pushing for security in their organisation and still be hacked. Should he/she face jail now?

I'm fine for a judge and jury to decide what is and isn't actually criminal conduct and whether the EO was negligent in protecting customer data. It needs to be explicitly illegal first, though.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#36

"we did nothing" Who? These companies get sued, that is a reaction. Congress? Well if you make a law twice as illegal, I'm sure that will make it stop /s. No one wants to be hacked, let's not pretend there is no fallout from ignoring security.

Oh come on, do you think these companies are doing everything to protect our data? Why the hell is our credit card applications hosted online anywhere after they've been processed anyway? And for 14 years? No mate, making it doubly illegal (such as actually fining and imprisoning the negligence in leadership that chooses forgiveness over permission) would undoubtedly help. There are plenty of ways to keep our data se…

More practical would be the removal of the Board of Directors and the CEO of the corporation, with the forfeiture of any unpaid future compensation and the ineligibility to serve as a director or officer of any other corporation. They are responsible for setting the policies and providing the resources to secure the corporation's data, and they have failed.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#37

Earlier quoted context omitted.

CapitalOne disclosed that this hack is going to cost them between $100mm and $150mm, which is a lot more than JSTOR would have lost from Aaron Swartz's "hack" of academic humanities papers.

Right, but it wouldn’t have happened if they hadn’t had such lax security, and I would argue that capital one are liable here for failing to adequately safeguard consumer data. If you properly secure your stack, you don’t get hacked. If they had fallen victim to some undisclosed zero-day, I’d feel bad for them - but in this case it appears to be misconfigured VPC SGs. Their error. Inadequate processes. We are also al…

"If you properly secure your stack, you don’t get hacked." Thats absolutely not true. You do reduce the chances of being hacked and you might reduce time it takes for you to discover the breach and you will be able to contain it quicker.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#38
post #19
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

One of many basic cultural differences between the UK and the EU. In the EU you must give up your biometrics (fingerprint) by law. Doesn't surprise me that they are leaving.

All the UK passports and non-national resident ID cards are facial biometric.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#39
post #19
post #9

Earlier quoted context omitted.

That's not the case in the UK - we don't have any single government issued identity document/card that everyone has to have.

One of many basic cultural differences between the UK and the EU. In the EU you must give up your biometrics (fingerprint) by law. Doesn't surprise me that they are leaving.

I think surveillance techniques and invasion of privacy are often spearheaded by the UK. I remember the CCTV cameras where everywhere long before other countries leveraged them at that scale.

Re: Capital One’s breach was inevitable, because we did nothing after Equifax

#40
In my opinion organizations still don't rely enough on "defense in depth" techniques to protect sensitive data. Breaching the WAF and gaining access to S3 files shouldn't suffice to gain access to the raw data. Personal data that is not required for transactional use should be either encrypted, pseudonymized or anonymized. I couldn't find information about the exact use case of the data but as it was stored in S3 I would guess that it was "set aside" for future use in analytics or machine learning, maybe? If so there's really no reason to store the raw data.

Any single IT system is hackable and will eventually be hacked. The probability that an adversary will be able to hack multiple, independent systems is much lower though, and would in many cases prevent data breaches like this one.

Post reply on HN