Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

331–340 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#331

Earlier quoted context omitted.

Isn't Equifax a government organization? How do they have severance packages?

You'd think that one of the credit bureaus responsible for maintaining the most sensitive data, and making it difficult for people to get affordable housing would be a government institution, but nope.

Would you rather have a government agency assign credit scores? The abuses would be rampant. Right now there is one party openly pushing to restrict voting access to people who are likely to vote for the other party, and a few years ago that same party enacted a new tax code that almost surgically penalized the residents of states that supported the other party; do you really trust such politicians to set up a fair credit rating system? I can see the headlines already: "SCOTUS rules 6-3 in favor of GOP effort to depress credit scores in Democrat-leaning cities," or perhaps, "Northeast states fear wave of foreclosures following GOP overhaul of credit score bureau," or maybe, "Whistleblower: President pressured credit rating agency to attack CNN, NYT reporters."

Equifax and the other ratings agencies have plenty of problems, but none of those problems are solved by having the government run things and many new problems would be introduced.

Re: US companies hit by 'colossal' cyber-attack

#332
And despite this, most companies are trying to get senior software developers for the AppSec programs but can't because they don't want to pay senior software developer salaries, or even software developer salaries. So the positions remain open, month after month, sometimes year after year.

I've been told several times this is because AppSec is considered by higher management to be mostly a clerical type position or at best, Application Support. Which would be fine if that were the level of experience and bundle of skills they were trying to hire, but it's not. What makes things even more difficult is that many companies have a policy of only hiring citizens and permanent residents for these positions but have outsource rates floating in their heads.

If you want to have an AppSec group populated with people who can explain (and often argue) security vulnerabilities in the code of others, you're going to have to pay for someone with enough experience to do so credibly (or you'll lose buy-in from developers) and knowledgably (so you're not wasting developer time with false positives).

Re: US companies hit by 'colossal' cyber-attack

#333
post #271

Earlier quoted context omitted.

I mean you're not even putting any efforts into your delusions. These are things that have been long debunked with very simple logic. My favorite part is how you believe that the big bad conspirators removed Trump and are pushing the vaccine, but back here in reality, Trump was the biggest champion of the vaccines. He created the program that got them into production so quickly. I don't know why I'm wasting the keyst…

The answer to the question “do crazy people know they are crazy” is a firm “absolutely not” and the comment you’re replying to proves that. Don’t bother replying, it’s always the same. If they reply at all it will be with a mix of half-truth personal anecdotes, scientific-sounding nonsense, paranoid delusions and if you’re really unlucky outright antisemitism. They are far gone and they don’t know it yet, there isn’t…

Agreed 100%

Re: US companies hit by 'colossal' cyber-attack

#334
post #260
post #209

Earlier quoted context omitted.

I don't think it is - I think it's cultural and organisational. The CFO and Finance in general see businesses as capital flows, they don't see value being added - just opportunities for leverage and cash management. The description of a cost center is a labelling denoting a target for removal and reduction - the destruction of value that occurs (typically 12 -24 months after the exercise) is seen as disconnected and…

Eye of the beholder topics don't generalize. If your CFO and Finance team is doing things like laying off all the information security people since they thought Axa would pay the ransom gangs, then state the name of the company. Otherwise it's just venting handwavy frustration about people whose job requires taking risk mitigation seriously.

I'm not going to name companies as I don't fancy the blowback, but the fact is that CFO's aren't doing risk minimisation, they're doing bonus optimization.

There is a common misconception that CFO's fiduciary duty to their shareholders determines that they should protect the long term stability of the company, but now most shareholders are in the company for 6mths tops. The duration of a CFO's fiduciary duty is arguably about 6mths out. The devastation of large companies in the economies of the west since 1980 is a testament to this.

Re: US companies hit by 'colossal' cyber-attack

#335

Earlier quoted context omitted.

Isn't inflation above gains essentially a devaluing of the market? If the stock market goes slightly down and inflation ramps up significantly isn't that the same as a crash?

The most expensive and valued stocks are "essentials" they dann just increase there price with inflation. I dont understand the problem with inflation..

Yes that’s exactly my point. People look at absolute value of the stock market but what matters is the relative value to the dollar.

Re: US companies hit by 'colossal' cyber-attack

#336

These digital networks and devices have become so complex we can’t reason about them, or in any case can’t easily reason about them given the resources available to most of the organizations running them. However, from what I’ve seen, most of these attacks are successful because these organizations are simply neglecting best practices (e.g. patch management, whitelisting, security awareness training).

> or in any case can’t easily reason about them given the resources available to most of the organizations running them.

I really feel this. Any new piece of software needs a level of ongoing maintenance that no one seems to realize, not even many software engineers I've worked with.

You can't "just" toss a binary onto a VM and forget about it. But all the work required to secure that and keep it secure is so invisible to management.

And because the work is invisible, it might even hamper career growth. So good luck getting either management or devs to prioritize all the security tasks they should be prioritizing.

Re: US companies hit by 'colossal' cyber-attack

#337
post #201

Earlier quoted context omitted.

Isn't Equifax a government organization? How do they have severance packages?

It's a para-state agency; while Americans don't have ID cards because they're afraid of surveillance, a private company having a complete database of everyone and veto power over mortgages is fine because it's a private company.

The existence of credit scores has tangible benefits that we take for granted. Without such databases we would all pay much higher interest rates and many more people would be denied loans. Very wealthy people would have little trouble, but low- and middle-income people would find it far more difficult to buy a house or a car. The reason it is better to be run by a private company than the government is not that surveillance, but the near-certainty (at least after everything we saw happen over the past 5 years) that a government credit scores agency would be politicized. We would have the same problems we have with equifax, and a whole new set of problems as e.g. the political party that rewrote the tax code to punish people who voted against them tried to weaponize credit scores.

Re: US companies hit by 'colossal' cyber-attack

#338

Earlier quoted context omitted.

You'd think that one of the credit bureaus responsible for maintaining the most sensitive data, and making it difficult for people to get affordable housing would be a government institution, but nope.

Would you rather have a government agency assign credit scores? The abuses would be rampant. Right now there is one party openly pushing to restrict voting access to people who are likely to vote for the other party, and a few years ago that same party enacted a new tax code that almost surgically penalized the residents of states that supported the other party; do you really trust such politicians to set up a fair c…

Then why is the SEC public, it could arbitrarily issue fines and fuck with the share price of any company that didnt donate to your party, maybe it should be private too?

Re: US companies hit by 'colossal' cyber-attack

#339
post #317
post #165

Earlier quoted context omitted.

It's worse than PII leaks and CEOs stepping down. Lax security has become scary. The U.S. Nuclear Weapons Agency was breached shortly after SolarWinds. Let's also not forget about OPM.

Except everyone forgot about OPM.

What is OPM ? Office of Personnel Management ?

Re: US companies hit by 'colossal' cyber-attack

#340

Earlier quoted context omitted.

Please point out some 10Q/10K filings that go into detail about these enormous expenditures related to security breaches. The SEC EDGAR database [0] is where you can find public quarterly financial statements and forward guidance from management (which will definitely mention the security breach related expenses), for every US-listed publicly traded company. Good luck! [0] https://www.sec.gov/edgar/searchedgar/compan…

Literally the first company I pulled up, Capital One, has this in the 2020 10-K: >During the year ended December 31, 2020, we incurred $66 million of incremental expenses related to the remediation of and response to the Cybersecurity Incident, offset by $39 million of insurance recoveries. To date, we have incurred $138 million of incremental expenses, offset by $73 million of insurance recoveries pursuant to the cy…

Aren't they just fixing leaks in the ship that should have been adressed years ago? If these are expenses on their infrastructure, thats not really losses, its an investment.

Losses would be their customers abandoning them in droves, or having to pay out massive fines.

Post reply on HN