Equifax securities fraud class action [pdf]
91–100 of 227 posts
Re: Equifax securities fraud class action [pdf]
#92Scrolling through the comments I'm surprised (and not all at the same time) no one has made a comment like this: So what? If an attacker is able to reach your DB the ballgame at 90% of the way over already. Yes I understand that a strong U/P on the DB server would be 1 final gate but unless I'm living in some alternative reality I can tell you plenty of companies use weak/shared/guessable passwords for stuff that sho…
Assuming patched, modern database software, that should keep attackers at bay until all the failed login attempts are spotted. It's very embarrassing that they (allegedly) did not do this. Of course, note that in this case it's a custom web application so it would probably be at least more of a challenge to compromise.
Re: Equifax securities fraud class action [pdf]
#93This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…
Challenge 2 is actually getting any legislator / regulator (at least in the United States in the current climate) to agree that this is an important and urgent regulatory matter worth adding the burden to companies', and that they should move on this now to improve overall national security.
Challenge 3 is to only make the request once, in a standard format so that the data is actually relevant instead of overlapping requests from different organizations that turn useful data into a paperwork drill that is irrelevant by the time it leaves the org.
Lastly, I'd say some sort of open source middleware proof of concept to exchange this information would go a long way toward accountability. Industry could even propose the best option themselves via their existing interest groups.
Re: Equifax securities fraud class action [pdf]
#94Scrolling through the comments I'm surprised (and not all at the same time) no one has made a comment like this: So what? If an attacker is able to reach your DB the ballgame at 90% of the way over already. Yes I understand that a strong U/P on the DB server would be 1 final gate but unless I'm living in some alternative reality I can tell you plenty of companies use weak/shared/guessable passwords for stuff that sho…
Sure they might eventually break those too, but it's time and effort and opportunity to be caught.
Re: Equifax securities fraud class action [pdf]
#95Note that this is an order on a motion to dismiss; none of the fact claims reported here are findings by the court, they are allegations made against Equifax. In a motion to dismiss, the facts in dispute are viewed in the light most favorable to the non-moving party, and here Equifax and other defendants are moving to dismiss. That's why the supporting reference for every fact claim is to the complaint against Equifa…
Re: Equifax securities fraud class action [pdf]
#96Dismiss as in the same penalty Equifax had to pay per breached user.
Re: Equifax securities fraud class action [pdf]
#97This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…
Right. We do this with accounting firms, and I think we should do it with data security as well. Does it cost money? Sure. But that's the cost of doing business. If you have personal info like this and you profit from it, then you are also responsible for safeguarding it.
They're all merging again post-Arthur-Anderson scandal with their services consulting businesses and while there may be controls and training and they're all pretty serious about it (I worked for such a company at one point) it doesn't seem like many folks are getting dinged on violations of late.
I agree that it is worth the cost (as a citizen whose data is being lost) but in the current landscape the companies may argue that it is not, and might be right.
Re: Equifax securities fraud class action [pdf]
#98This is quite strong policy. Usually in most sinister incompetent companies, the user name is "admin" and the password is "password". On a serious note: there should be a mandated, periodic, third-party security audit by neutral parties for all entities which deal with user data beyond a certain specified level of sensitivity. It should not be left to their discretion when to run such an audit from their end. Whether…
Re: Equifax securities fraud class action [pdf]
#99> On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax’s legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, G…
Re: Equifax securities fraud class action [pdf]
#100Earlier quoted context omitted.
Colleague #4-20: Build various integrations to database, all with their own ways of storing credentials. Colleague #2: "It's really past due time to change the database password, but first we have to make sure all critical systems can still access the database."
Which is why forward planning and prompt action is worth so much. I know I'm stating the obvious, but I've seen some worrying attitudes of "just in time" that seem to go hand in hand with a misunderstanding of Scrum Sprints or Kanban. Where people concentrate on the tree and ignore the vast interconnected forest around them.