Live data from Hacker News

Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

bloomberg.com

51–60 of 80 posts

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#51
post #18

IMPORTANT: The date of disclosure is ALSO the date that demand for hacked data explodes. It's good practice to have a staged-disclosure procedure for leaks of this nature. For example: your bank should be told to start fine-tuning its anti-fraud capabilities BEFORE the entire world is made aware that you can be defrauded in this particular manner.

That's really interesting. We noticed a statistically significant number of declines on debit/credit cards roughly 1 week before Equifax publicly disclosed.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#52
post #48
post #36

Earlier quoted context omitted.

If that's the case, we must assume then that any recommendations they made were summarily ignored, given the subsequent breach in July?

They did not disclose details of the engagement so hard to speculate on anything. It somewhat unusual for the name to be disclosed though.

That caught my eye as well.

It would not be a bad strategy at all to leak the names of as many potential scapegoats as possible if one were avoiding accountability.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#53
post #41

Earlier quoted context omitted.

Right, and these execs did that as well. I mentioned that in the "routinely liquidate" part, but I guess it wasn't clear, they do liquidate shares on a schedule. Sure, doing anything out of that schedule is always a risk, and doing things on that schedule doesn't mean there isn't insider trading still happening. A successful prosecution under these equities-specific market sanctions will rely on more than that.

I'm under the impression that these were not 10b5-1 sales.

I am too, since I read TFA and it says -- twice, I think -- that they weren't.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#54

I do performance / app triage work, but see the same thing. Often I walk in to a supposed "emergency" only to discover the problem has been occurring for months, if not years. Often, there is a significant cost (IE: in the millions) but either the organization isn't willing to remediate, or isn't even aware of the full scope of the cost (IE: "It's not my budget so I don't care"). In at least one case, I came across a…

I came across a "hole" in the design of a vendor I was evaluating. Their fancy Java UI actually just downloaded plaintext root credentials to their MySQL database. All security was client side. As a bonus the root credentials were debug logged to the user's local computer. Making it worse, they actively sold this as a multi-tenant platform to be used with mutually untrusting parties. When I met with engineering and s…

This stuff is really the ultimate technical debt. Fixing it seems to provide zero benefit today. But there is a significant chance that one day it's an extinction event (or just a billion-dollar blunder, if you're big enough to survive it).

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#55
Here's a question. What if based on this hack and others, someone decides to publicly post all the details they are aware of. So basically I can go on a website and look up all the hacked SSNs and the person and their information associated with that. How will the US cope with that?

The reason I ask that question is that it's definitely not gonna happen. But it's arguably a lot better than the situation right now where we have a few malicious actors who do have that information. If the data was completely public I feel you'd have a huge effort to fix the problem bwcahwe your neighbor can look up your credit worthiness. Yet I think the situation right now is worse because we won't have that effort to fix the problem yet 95% of the people who would have caused you problems have that data.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#56
post #36

Earlier quoted context omitted.

If that's the case, we must assume then that any recommendations they made were summarily ignored, given the subsequent breach in July?

You also have to look at the scope of the work performed too, wouldn't you?

Hard to imagine a competent security review would not point out "Your entire database is accessible directly from the web server and you have no verified plan or demonstrated capability to deploy security patches to the web server within a reasonable timeframe"

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#57
post #38

Earlier quoted context omitted.

Sure, that combined with the fact that courts simply refuse to refer to anything involving software a 'negligence', no matter how extravagantly negligent it might be, would make that a pretty good strategy. The only flaw in it, really, is that it would also open you up to things like the Sony hack which actually had them shut down operations for awhile. As much as companies REALLY do not want to ever admit it, no mat…

Maybe this is the unintended benefit of companies like domino's claiming they're a "tech business that sells pizza". I'd love to see that language used in an agument that the company has made tech it's core competency and that lowers the bar for negligence.

I imagine it would depend on the nature of negligence: were they to leak customer data, they would be treated as a tech business; were they to poison customers, they would be treated as a pizza business.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#58
post #57
post #38

Earlier quoted context omitted.

Maybe this is the unintended benefit of companies like domino's claiming they're a "tech business that sells pizza". I'd love to see that language used in an agument that the company has made tech it's core competency and that lowers the bar for negligence.

I imagine it would depend on the nature of negligence: were they to leak customer data, they would be treated as a tech business; were they to poison customers, they would be treated as a pizza business.

The pizza is probably produced by others, in the spirit of the gig economy. That way the company can defend any lawsuit.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#59

Here's a question. What if based on this hack and others, someone decides to publicly post all the details they are aware of. So basically I can go on a website and look up all the hacked SSNs and the person and their information associated with that. How will the US cope with that? The reason I ask that question is that it's definitely not gonna happen. But it's arguably a lot better than the situation right now whe…

What would I do with that though? As a resident of a country that's affected, if I hit a profile that happens to have fraud protection, I go to jail. Now, if I was in a country not so friendly to the US I might have a shot.

Re: Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed

#60

Earlier quoted context omitted.

Username related; please don't.

Coincidentally this is the second time today I've seen a profile description that took a real hard line against people not using their real names. I never realized "real name elitism" existed on HN

Perhaps "about: payment tech" explains it.
Post reply on HN