Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

81–90 of 227 posts

Re: Equifax securities fraud class action [pdf]

#81
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Its probably been admin/admin for the past decade as well

Re: Equifax securities fraud class action [pdf]

#82
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

There are two types of possible regulation, one is control and the other is liability.

With control, some administrative body says you have to do X, Y and Z. And presumably, if you jump through the hoops and it blows up, there is an implicit guarantee. This kind of regulation is common across banks, and in 2008 when all the reserve requirements were deemed insufficient and all the acceptable ratings meaningless, there was a bailout.

The other alternative is a liability approach. You are liable for something (e.g. protection of customer information) and you are responsible for execution in the best way to know possible. If you fail, there is some punitive measure taken.

I personally prefer the second, especially since security is a hard problem. There are best practices, sure, but from my experience, I don't believe regulators and auditors are effective in their stated goals.

Re: Equifax securities fraud class action [pdf]

#83
post #8

Earlier quoted context omitted.

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

Colleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will…

Source: https://news.ycombinator.com/item?id=21312609

Re: Equifax securities fraud class action [pdf]

#84
Scrolling through the comments I'm surprised (and not all at the same time) no one has made a comment like this:

So what?

If an attacker is able to reach your DB the ballgame at 90% of the way over already. Yes I understand that a strong U/P on the DB server would be 1 final gate but unless I'm living in some alternative reality I can tell you plenty of companies use weak/shared/guessable passwords for stuff that shouldn't be reachable from the outside like this. And honestly? Securing the DB with 1 extra (potentially useless) line of defense is an extremely low priority for most businesses.

Re: Equifax securities fraud class action [pdf]

#85

I’m genuinely curious how this happens. I remember my first job in the industry, just out of university. I knew nothing about security, but still wouldn’t have done that. My first gig was in a credit union software company, and the security standards were nonexistent, yet we still had more reasonable passwords than this (which sounds like an installation default).

This happens when a 3rd party is asked to install a system and the first party never takes ownership of securing it.

Re: Equifax securities fraud class action [pdf]

#86

Why is Equifax still a thing?

This was my thought. Why do we need three credit reporting agencies? TransUnion and Experian should be enough. I go through my reports and all three are pretty much the same.

Duopolies and Monopolies are far worse for markets than those dominated by 3 or more entities. Getting rid of one of the agencies will only result in more price-fixing and abuse by these companies.

Re: Equifax securities fraud class action [pdf]

#87
post #55
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

The laws already exist, the penalty is just too small. With higher penalties there would be an insurance market where the insurers set standards and performs audits. Standards set by buerocrats are usually written by special interest groups and don't achieve the desired outcome at a good cost.

Sadly having been in such an environment, I can confirm that indemnity insurance exists for such situations. What happens is the underwriter to reduce risk mandates a very rigid process.

In one case, I saw a "private cloud" provider underwrite their client's system by owning the "software-development-release-cycle". They were mandating quarterly releases and three-month manual testing and regression periods.

They put themselves in a situation whereby they could charge the client for the tin, administering the process, the time and materials for the deployment and testing and the indemnity premium.

They reduce their risk/exposure because of infrequent releases and such long regression cycles meant assurance levels were rarely met within the dedicated window. There was a very long tail of unreleased features. In summary, they mitigated any risk by chocking the product, reducing the number of releases and the size of them to deliver a fraction of the value available.

We learned to work around by taking advantage of feature switching, but quarterly releases are a death knell for a product.

Re: Equifax securities fraud class action [pdf]

#88
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

In a market where Equifax having a critical data breach threatened is bottom line, they'd be incentivized to implement this themselves.

A critical data breach doesn't threaten its bottom line. Unless someone uses such a breach to turbo credentials into one of the credit-querying institutions and reveals, for example, the detailed criteria by which such an institution grants a loan.

Re: Equifax securities fraud class action [pdf]

#89
post #45
post #8

Earlier quoted context omitted.

I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will change it later".

Good ol' "temporary permanent" solution. https://stackoverflow.com/a/778275

Thank you for that funny read, lots of great comments!

Re: Equifax securities fraud class action [pdf]

#90
post #82
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

There are two types of possible regulation, one is control and the other is liability. With control, some administrative body says you have to do X, Y and Z. And presumably, if you jump through the hoops and it blows up, there is an implicit guarantee. This kind of regulation is common across banks, and in 2008 when all the reserve requirements were deemed insufficient and all the acceptable ratings meaningless, ther…

I don't see much difference in the two approaches, except the later case will require customers to collectively sue you for damages, in which case you can probably run a cost-benefit analysis to find out if it would be worth it.

In a regulatory environment, if a corporation does not comply, the punishment is increased until either the corporation complies or seizes to exist. Since not existing is bad for profit, corporations usually comply eventually.

In a liablatory environment, as long as nothing happens, a corporation can continue to proceed down a dark path with no ill effects and abuse the rules as they see fit. It's only costly when things go wrong and you can calculate the likely cost of things going wrong.

Post reply on HN