Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

51–60 of 227 posts

Re: Equifax securities fraud class action [pdf]

#51
post #8

Earlier quoted context omitted.

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will…

nice meme

Re: Equifax securities fraud class action [pdf]

#52
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Right. We do this with accounting firms, and I think we should do it with data security as well. Does it cost money? Sure. But that's the cost of doing business. If you have personal info like this and you profit from it, then you are also responsible for safeguarding it.

Re: Equifax securities fraud class action [pdf]

#54
post #44

I'm using that headline as our thought of the day in group chat at work. Because that is just egregious and negligent. Nobody thought to raise that? to anyone? Although I can understand. I have several people who now call themselves DevOps on a project who have practically zero experience with systems operations _or_ development, and have done some utterly incomprehensibly stupid things. It doesn't matter how fancy y…

This can happen for many reasons. People just want to get whatever it is working. There is probably a lot of time delivery pressure and something like IAM is complicated. IMO, the first step to fixing the problem is give DevOps the proper amount of time to design the required permissions. It sounds easy from the outside, but again IAM can be very complex. Additionally, DevOps must think security first. That means a n…

Yes, least possible permissions is a tried and tested axiom that should be foremost in people's minds. The same with layered security in depth, disabling unneeded accounts, etc etc.

I'm seeing a lot more inexperienced people getting access to stage/production systems (i.e. internet-facing to a greater or lesser extent) due to the DevOps paradigm. Of course the role sounds cool so people advertise for it, and apply for it, but there's a serious lack of understanding of just what it is! Developers need a good understanding of Operations, and Operations Admins need a good understanding of Development.

Things like not understanding the reason why you'd want to test the network access and DNS lookup from the stage pods instead of their local machine. Or not knowing how to perform basic source control tasks.

Of course, I can be dismissed as a grumpy old man. I am, I'm in my 40s and 23ish years of Linux operations has, I hope, taught me a couple of lessons. But I'm not yelling at the kids to get off my lawn, I want to teach the kids about correct garden maintenance, weeding, and when to plant bulbs and seeds (to stretch a metaphor way too far!). I find people are resistant to learning basics "because the cloud", or putting in due diligence because they're paid too little (which I fully understand!)

Sorry, grumpy old sysadmin who is now a team lead with lots of responsibility and too little time to brain dump his 20+ years into some younger heads. I'll try to lighten up :)

Re: Equifax securities fraud class action [pdf]

#55
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

The laws already exist, the penalty is just too small. With higher penalties there would be an insurance market where the insurers set standards and performs audits.

Standards set by buerocrats are usually written by special interest groups and don't achieve the desired outcome at a good cost.

Re: Equifax securities fraud class action [pdf]

#57
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Unfortunately this particular genie is already out of the bottle. We can improve security practices going forward, but at this point any American with a credit history has had their personal details compromised.

Re: Equifax securities fraud class action [pdf]

#58
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

No way! A sinister big company would use “Pa$$w0rd” to meet complexity requirements!

Re: Equifax securities fraud class action [pdf]

#59
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

i think it's 123456 because users get confused on the phone.

- What's the password

- password

- Yes, the password!

Re: Equifax securities fraud class action [pdf]

#60
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

There could be whistleblower protections for hackers. Consider the previous attitude was hackers are causing millions of dollars of damage and need to be thrown in prison. With the proliferation of state sponsored and counter intelligence hacking over the past 15 years, no one believes you can make anything secure just by throwing enough teenage script kiddies in federal prison.

The reverse now is companies are taking the blame and legal liability for being negligent in their security practices.

That said, no organization public or private is impervious. Heartbleed and meltdown should have driven that home to anyone who thinks otherwise. Determining where the line of negligence lays will be a harder one to draw, though for civil liability it may not even matter (which is great for Google, Apple, and death for small businesses.)

Post reply on HN