I just read about how the hack was done. Shockingly stupidly easy! 1. They realized that Equifax uses Struts. 2. They modified struts! and 3. Equifax used the updated code on their servers. DUUUUUHHHHHH!
Equifax’s Maddening Unaccountability
51–60 of 238 posts
Re: Equifax’s Maddening Unaccountability
#52There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?
All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very similar to Google, et al. We aren't the consumer. They collect our personal information, vastly more than credit agencies. And the real customer are the advertisers who pay Google. The difference is, we probably trust Google more than Equifax (even before all of this).
A month ago, my mom said she wanted to start using Uber on her phone. I explained how to install it, and when she did (as well as the Lyft app for that matter) it wanted access to her camera, photos, contacts, a list of information on her phone. And she said fuck no. And refused to give permission. So she still uses cabs and pays cash.
Re: Equifax’s Maddening Unaccountability
#53Earlier quoted context omitted.
Expecting perfection is wrong. There's 120 millions of lines of code in an A380, and planes don't crash due to software bugs. Why is it wrong to expect perfection in critical infrastructure? Something went wrong somewhere in software engineering. My HP42s calculator has about 6 insignificant bugs that you need to get out of your way to trigger. Your new cellphone on the other hand, when you turn it on it downloads a…
You're comparing a relatively cheap credit report to a $400 million dollar airplane with a 15-25 billion euro program cost. Not to mention aerospace has a 100 years of innovation and has actual lives at stake. The internet, what 30ish years? Not to mention network security is a relatively new concern.
Why is software immune? You ask yourself about cost of the Office of Personnel Management hack from two years ago, and before that it was the biometrics database from the USCIS.
Re: Equifax’s Maddening Unaccountability
#54Earlier quoted context omitted.
Thats exactly what I'm saying. There is near zero incentive for congress to enact consumer protection legislation.
There's incentive (as it's their job, or is said to be). What there isn't is a downside if they don't.
Re: Equifax’s Maddening Unaccountability
#55Earlier quoted context omitted.
Equifax has an $18B market cap. Can you name one instance of a government imposed fine for improperly stored PII exceeding even $100M? Furthermore, do you have evidence that the PII was improperly stored, or that Equifax's security practices were lacking in any way? The vulnerability provided full RCE, and I know of no info-sec magic that inoculates you against that.
Having root on a web server shouldn't give you access to 147 million customer records.
I'm wondering if Equifax is using Struts-provided REST for its entire architecture. If that's the case, gaining access to the web server was only the first step. From there the attacker could perform RCE on sensitive services.
Re: Equifax’s Maddening Unaccountability
#56Earlier quoted context omitted.
I'm not sure they actually care in Washington. I was impacted by the OPM breech. I got a form letter and some credit monitoring. All that outrage and, as near as I can tell, not a damned thing has changed. I might be biased and jaded.
Thats exactly what I'm saying. There is near zero incentive for congress to enact consumer protection legislation.
Re: Equifax’s Maddening Unaccountability
#57There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?
Common misconception. They actually do need your approval, it's just that that approval is buried in the mountains of legalese you sign whenever you sign up for a bank account, credit card or loan.
Re: Equifax’s Maddening Unaccountability
#58There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?
We have all agreed. We gave permission to any company that extends credit. They give our information to these credit reporting agencies on an on-going basis, personal information, including what our payment behavior and history is. All of this comes down to trust. We trust our banks and credit card companies. They trust Equifax. Equifax's customer is your bank or credit lending company, not us. It's actually very sim…
Re: Equifax’s Maddening Unaccountability
#59Earlier quoted context omitted.
Expecting perfection is wrong. There's 120 millions of lines of code in an A380, and planes don't crash due to software bugs. Why is it wrong to expect perfection in critical infrastructure? Something went wrong somewhere in software engineering. My HP42s calculator has about 6 insignificant bugs that you need to get out of your way to trigger. Your new cellphone on the other hand, when you turn it on it downloads a…
You're comparing a relatively cheap credit report to a $400 million dollar airplane with a 15-25 billion euro program cost. Not to mention aerospace has a 100 years of innovation and has actual lives at stake. The internet, what 30ish years? Not to mention network security is a relatively new concern.
Re: Equifax’s Maddening Unaccountability
#60Earlier quoted context omitted.
Having root on a web server shouldn't give you access to 147 million customer records.
I'm eagerly awaiting the technical details of the attack. If it turns out that their web server has 100% unfettered access to the database then I'll gladly pick up a pitchfork as well. I'm wondering if Equifax is using Struts-provided REST for its entire architecture. If that's the case, gaining access to the web server was only the first step. From there the attacker could perform RCE on sensitive services.
You may want to think twice. Try to design an architecture that doesn't have that. If you think it through, you'll realize the best you can do is not to deny access, but to monitor access so that any statistical deviation in requests-per-hour will trigger an alarm. Yet nobody does that, so why should Equifax have been a pioneer in this method?
This is the uncomfortable truth that everyone is obscuring here. There wasn't a solution. Equifax got owned, and they happened to have a trove of data. Everyone now wants to see their heads roll, but you too would find yourself in the same situation if you have an RCE on your servers.