Live data from Hacker News

Equifax securities fraud class action [pdf]

securities.stanford.edu

91–100 of 227 posts

Re: Equifax securities fraud class action [pdf]

#92

Scrolling through the comments I'm surprised (and not all at the same time) no one has made a comment like this: So what? If an attacker is able to reach your DB the ballgame at 90% of the way over already. Yes I understand that a strong U/P on the DB server would be 1 final gate but unless I'm living in some alternative reality I can tell you plenty of companies use weak/shared/guessable passwords for stuff that sho…

I agree it's not ideal that something so important wasn't at least only accessible by VPN but any decent IT professional knows to set a strong password like this, because it's so easy to do so - sometimes you can't just use a VPN because of historic reasons or due to the complexity of the network but you can certainly set a strong password on a database server.

Assuming patched, modern database software, that should keep attackers at bay until all the failed login attempts are spotted. It's very embarrassing that they (allegedly) did not do this. Of course, note that in this case it's a custom web application so it would probably be at least more of a challenge to compromise.

Re: Equifax securities fraud class action [pdf]

#93
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Determining which organizations should be charged with third-party security audits / regulation in an already complicated regulatory landscape (orgs may already be providing security info to 2-3 regulators in different formats is challenge 1.

Challenge 2 is actually getting any legislator / regulator (at least in the United States in the current climate) to agree that this is an important and urgent regulatory matter worth adding the burden to companies', and that they should move on this now to improve overall national security.

Challenge 3 is to only make the request once, in a standard format so that the data is actually relevant instead of overlapping requests from different organizations that turn useful data into a paperwork drill that is irrelevant by the time it leaves the org.

Lastly, I'd say some sort of open source middleware proof of concept to exchange this information would go a long way toward accountability. Industry could even propose the best option themselves via their existing interest groups.

Re: Equifax securities fraud class action [pdf]

#94

Scrolling through the comments I'm surprised (and not all at the same time) no one has made a comment like this: So what? If an attacker is able to reach your DB the ballgame at 90% of the way over already. Yes I understand that a strong U/P on the DB server would be 1 final gate but unless I'm living in some alternative reality I can tell you plenty of companies use weak/shared/guessable passwords for stuff that sho…

Defense in depth is important in organizations for exactly this reason. It only takes one admin falling for a well crafted phishing email to get an insider in your network, which is why you need to design it in a way where they find a whole new set of roadblocks once they're inside.

Sure they might eventually break those too, but it's time and effort and opportunity to be caught.

Re: Equifax securities fraud class action [pdf]

#95

Note that this is an order on a motion to dismiss; none of the fact claims reported here are findings by the court, they are allegations made against Equifax. In a motion to dismiss, the facts in dispute are viewed in the light most favorable to the non-moving party, and here Equifax and other defendants are moving to dismiss. That's why the supporting reference for every fact claim is to the complaint against Equifa…

So, the footnotes for the "admin" "admin" (46. Id. ¶ 225 (emphasis omitted) points at footnote 1. Am. Compl. ¶ 3.) claim refer to the amended complaint, paragraph 3? Any idea where this amended complaint is, which most of the early footnotes are referring to?

Re: Equifax securities fraud class action [pdf]

#97
post #52
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

Right. We do this with accounting firms, and I think we should do it with data security as well. Does it cost money? Sure. But that's the cost of doing business. If you have personal info like this and you profit from it, then you are also responsible for safeguarding it.

Just a quick gut-check: are we sure this is working well with accounting firms?

They're all merging again post-Arthur-Anderson scandal with their services consulting businesses and while there may be controls and training and they're all pretty serious about it (I worked for such a company at one point) it doesn't seem like many folks are getting dinged on violations of late.

I agree that it is worth the cost (as a citizen whose data is being lost) but in the current landscape the companies may argue that it is not, and might be right.

Re: Equifax securities fraud class action [pdf]

#98
post #48

This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…

It's "Password12345!" to work around the complexity requirements.

Re: Equifax securities fraud class action [pdf]

#99

> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…

This is blatant insider trading. That however does not preclude you from being crazy, nice try.

Re: Equifax securities fraud class action [pdf]

#100

Earlier quoted context omitted.

Colleague #4-20: Build various integrations to database, all with their own ways of storing credentials. Colleague #2: "It's really past due time to change the database password, but first we have to make sure all critical systems can still access the database."

Which is why forward planning and prompt action is worth so much. I know I'm stating the obvious, but I've seen some worrying attitudes of "just in time" that seem to go hand in hand with a misunderstanding of Scrum Sprints or Kanban. Where people concentrate on the tree and ignore the vast interconnected forest around them.

Hence the old adage: days of work can save you hours of planning.
Post reply on HN