We have the technology to build vastly superior replacements right now. It's mostly network effect requirements that make this extremely challenging/slow to implement.
An example of something we could do is cryptographically authenticated web-of-trust creditworthiness estimation, with techniques like proof of burn and selective trust anchoring used to establish terminal nodes in the unrolled trust DAG. This sort of thing would allow for pseudonymous, automated determination of trust without the extreme security and privacy risks posed by centralized identity stores like the credit bureaus.
Which means each and every line of code was written by the lowest bidder.
A meritocracy is not born when rich corporations (buyers of labor) select vendors (sellers of labor) based on personal connections and not ability to do the job
Leadership sets the priorities, and expectations. They get paid disproportionately more than other employees and I think they should be scrutinized and bear responsibility correspondingly.
But I have no doubt they probably found someone lower in the ranks as a scapegoat.
"Joe was in charge of patches. And we are all equally disturbed and horrified by his behavior. But we've reached out to him and let him go. Now give us more of your personal information so you can get free credit monitoring for 6 months [+]. -Sincerely and with deeper regrets, the Executive Team [++]"
[+] (fine print) then charged as $49.99 a month until cancelled. To cancel please visit one of the 3 Equifax location in person on the first Wednesday of the month. Accepting
[++] (even finer print) by accepting the free credit monitoring you agree to binding arbitration and forfeit your rights to participate in a class action suit against Equifax and its subsidiaries.
If he had a CS degree, that wouldn't make him any less responsible for this massive data leak.
If I got the story right, this bug was present for the last 9 years and patched upstream a couple days before the leak. Some measures could have prevented its exploitation or reduced its impact, like throttling by IP, one-time session keys and so on - and should be in place for any serious application - but it's entirely possible they had fixed schedule for patches and mis-evaluated this flaw as non-critical.
A LOT of companies carry obsolete dependencies for a long time.
Reasons are:
• It's hard to find technically skilled people who want to spend all day doing management tasks.
• It's easy to find essentially unskilled people who do want to spend all day doing management tasks.
• There is a large set of unwritten rules and social expectations that the people who created and run such companies use as proxies for competence. Do you dress nice, can you play an enjoyable game of golf, are you married, how old are you, etc. These proxies invariably de-select the kinds of people who have a deep understanding of their field (i.e. single young men who are able to devote enormous hours to their craft).
Edit: note the recommendations in her LinkedIn page. Every single one talks about her collaboration and communication skills, not a single mention anywhere of technical skills. It's tempting to shoot "Susan M" here but the real issue is a boardroom culture in which management is seen as a skill entirely divorced from the effort being managed.
This is extraordinarily evident in the distribution of engineer salaries.
A "tech" company is a company for whom technology (ie. developers) is a profit center rather than a cost center.
https://www.nytimes.com/2017/09/08/technology/seriously-equi...
That sounds to me like I don't own my own data.
I hope that this story will bring down the hammer on their heads - not just Equifax, all of them.
Creditor's public key, not private key.