Two top Equifax execs to retire after security breach
wsj.com
wsj.com
By the end of the interview, I felt sorry for her. I have no idea if she had relevant experience or not, she just sounded like someone who has been conditioned to argue that delays in new development are unacceptable, and that the cloud is inevitable, and if it costs more to do it right then you'll have to make do with less, and cetera and so forth. I'm not terribly shocked that they've taken down these interviews, but I am very sorry I didn't save a copy when I found them.
The interviews were still available for viewing as of 12:31pm Eastern Time on Sept 10, and there are transcripts that you can find following the links in the article, which has been updated to note the videos were scrubbed from the internet.
[1]: https://www.hollywoodlanews.com/equifax-chief-security-offic...
"The full interview videos went far in explaining what may have been the eventual cause of the massive leak of information now gravely affecting 143 million Americans."
Serious question, is there any way this might actually count as destroying evidence?
It says the interviews were removed by user, but I saw them and they were briefly still playable after they were first reported on. Someone must have been keen enough to snag a copy. They were eye opening.
The transcript does not include the quote that really brought it home for me, "resistance to the cloud is futile" – I wonder what else it does not include...
Take a car for example. If you're driving and you allow the car to hit someone and they die, you are charged with manslaughter. It's your responsibility to operate it safely. It doesn't matter if the conditions were difficult. In fact it's worse - you shouldn't have operated the car.
It's the same concept here. They were operating something dangerous and did not take the necessary steps to ensure our safety.
They should go to jail.
Though I think it's debatable whether leaking SSNs is comparable to manslaughter.
This also raises a real question about scale and distributed harm. If killing someone is wrong, what is stealing one ten-thousandth of a lifespan (through stress and monetary loss) from a hundred million people?
I can see the justification for those large compensation packages for CxO only when something like this happens they would bear the corresponding responsibility - maybe even forced to sell a few yachts or a few summer homes here and there maybe to offset the investigation costs even.
https://www.fastcompany.com/40468811/heres-why-equifax-yanke...
Look at what actually happened. Equifax was using the Struts framework. This is a very safe, popular choice. They were using what everybody else uses.
There was a critical vuln in the framework, and they failed to update their box for N months. But we're talking only a few months. N is very small -- maybe four? And yeah, you can argue that four months is an absurdly long time to have a known critical vuln in production. But I guarantee you that most people reading this work at companies that are similarly vulnerable. Attacks are simply rare.
Whatever company you work for, if you do not have regular pentests, you are no better off. And even if you do, it's overwhelmingly likely that you've overlooked some lonely outdated server that's still running on your network because Bob set it up a year ago and forgot about it and oh look now you have a pivot into your whole network.
It seems very strange to choose this one company and crucify them just because they lost your data. Everybody is insecure everywhere always, and we've learned to tolerate this by pretending it's not true or that it doesn't exist or that it's not a big deal. But you know what? It is true. That truth will continue to manifest itself in the years to come. No matter how much you'd like it not to be true, your stuff will still get stolen. Usually you just don't hear about it.
Yes, it was stupid for them to have everybody's PII attached to that one webserver. A single point of failure should never result in compromising the whole system. But think about how that architecture would work in practice. A customer service rep still needs to get at most of your data. It's a credit bureau. Where would the data be stored in a way that a remote code exec wouldn't be able to snag it?
Equifax's crime boils down to "they failed to run the equivalent of sudo apt-get upgrade on their framework." When you're managing a fleet of hundreds or thousands of machines, this is a situation that almost all of us have wound up in. If we can't get it right, why do you want the execs' heads to roll? Are you sure you won't be next on the chopping block?
Think about it this way: the time between "someone discovered a vuln in Spring" and "the attackers stole 150M credit reports" was just a few months. Are you sure Equifax wasn't a victim here? Someone threw a cinderblock through their window and made off with their trove of data.
Except of course, it wasn't a cinderblock through a window. It was completely silent. Even if your firewall is great, you can still smuggle data out of a network using DNS alone.
Food for thought.
We hold Equifax to a higher standard because of the nature of the data that it collects.
> Everybody is insecure everywhere always
Some of us think that's neither necessary nor inevitable.
> If we can't get it right, why do you want the execs' heads to roll? Are you sure you won't be next on the chopping block?
In some professions, including many engineering ones, gross negligence is punished with the removal of one's ability to practice professionally. It's imaginable that if there were consequences for one's actions, things wouldn't be "insecure everywhere always".
Really, how am I still finding people taking time out to defend the incredible ineptitude of a privacy-oblivious company in a hated industry?
You can disagree with that, but you'd be hard-pressed to justify that position. Six decades of computing history would contradict you. And as someone who saw the landscape of real-world codebases and deployments at nearly a hundred companies, there is almost always a way in. People are smug thinking their code is great till you show them an SQL injection that works, or pop up an alert(1) on their favorite front end framework.
The moment the world freaks out about this lack of security, we've all lost. Imagine a dystopian future where the only way to write consequential software is to have it approved by three committees. You might think that's how it already is, but we can move way farther in that direction. Just look at how hard it is to run a simple medical study.
We just expect a company that stores the highly personal information of hundreds of millions of people to have better security than that of a random blog site maintained by one guy in his basement.
If you don't feel that way, I propose asking some of your pentester friends how they feel about the breach. Somewhere between unsurprised and shrug, probably.
It doesn't change a thing that this situation demands higher security. We're fighting against forces of nature. Except instead of extinguishing forest fires, we're asking for the equivalent of no forest fires, ever, and arguing vehemently that modern technology is so good that forest fires should not have been allowed to happen.
No need to read the rest of your comment. I'm not biting.
Everyone either goes silent or describes an idealized architecture that has glaringly obvious flaws in regards to meeting business goals.
I think maybe the top ten companies in our industry do this at scale well enough to work. Maybe.
2) subscribe to a service that alerts on vulnerabilities in the assets listed in 1). Run Nessus scans. License cost you a bit over $1k a year.
3) invest in a resource to maintain the register and respond to alerts. Tie them into a governance model so management are aware of risks and can divert time and money when needed to mitigate
Security is a process not a technology. Nothing I've mentioned here is sexy or advanced.
What? It takes vigilance, training, competence, and a culture of security. Oh, and lots and lots of money backing it up. If your company isn't willing to make that commitment, then your company shouldn't legally be allowed to handle any sensitive data at all. The legal consequences of a leak will be moderated if it is proven, by fellow professionals, that a company took every standard precaution necessary based upon the sensitivity of the data in question. Nobody (except for perhaps yourself) seems to be claiming that Equifax's technical chops were anything but inept.
> Six decades of computing history would contradict you.
Feel free to actually cite anything at all supporting your position, rather than glibly appealing to inevitability.
> The moment the world freaks out about this lack of security, we've all lost.
As if we haven't already lost? The Equifiax leak is a privacy disaster of the highest order.
> Imagine a dystopian future where the only way to write consequential software is to have it approved by three committees.
I welcome this dystopia with open arms, if it means it can save us from defeatists who have given up on the idea that software doesn't have to be completely terrible.
I have personally breached companies that fit this description. That was my job, and it's why I was hopefully the last person to breach that particular facet of their landscape.
But pentests can't catch everything. That's the dirty secret that is also somehow not a secret. The very next commit could make that pentest obsolete. Ditto for spinning up a server.
As if we haven't already lost? The Equifiax leak is a privacy disaster of the highest order.
Well, what do you think will happen from this? That may be true, yet the world will go on. We've been trained to accept the current system as inevitable, but SSNs aren't a security mechanism. The underlying absurdity is that we view leaking them as a disaster rather than recognizing and replacing the fact that we all rely on their secrecy.
If someone wants to impersonate your identity, they can usually find a way. This breach will certainly make that easier, but I'm not sure it will affect the actual fraud rate. Time will tell.
(I'm aware far more than SSNs were leaked. The point is that it was a bad idea to have this central point of failure in the first place. If it wasn't Equifax, it would've been someone else.)
This is addressed by "vigilance". And no, we still aren't asking for perfect security. Even on human-scale timeframes, the odds of a single exploitable vulnerability being introduced in any aspect of the software, for even a moment, are 100%. But if it takes only a single vulnerability to completely exfiltrate the whole of a company's sensitive data, then you're going to be hard-pressed to find anyone calling that a securely-designed system. I'm sincerely sorry that a career spent in the trenches has left you so jaded and cynical, but we can do better, and hopefully we as an industry do so before the government looks at our inability to self-regulate and imposes double-secret-hyper-SOX on all of us.
Prison for CEO and the board should be the least we need to do.
Just because something you don't like happened doesn't mean someone goes to jail. This is the hard but important idea you have to learn in a civilized nation. Bad stuff happens, and you don't just get revenge on whoever is nearby. This was a crime entirely perpetrated by another party. You don't get to transfer their guilt onto someone who may have been reasonably diligent.
Now the issue on aggregating the data in the first place is another conversation.
In US we have a lot of what's called regulatory crimes. For example, https://www.law.cornell.edu/uscode/text/42/1320d%E2%80%936
Similar laws can be created to deter people from violating privacy of financial information. We can call what's happened a negligent disclosure financial information.
> This was a crime entirely perpetrated by another party.
I think I didn't make myself clear. I, personally, do not think the people who actually exploited the vulnerability should be the main target of any law enforcement investigation.
What I want to build are strong incentives to ensure that vulnerable data is as secure as possible. Unless the pressure goes to the top, this will not happen. This means that it is not enough to find a scapegoat in mid-management who might not have much of a say in how things run.
I don't even hate credit rating agencies. If the CEO and the board go to prison (or a slightly less desirable outcome if they don't and we get strong regulations to make sure people do in any such future incidents) will make the rating agencies stronger. They will be able to go to investors and say look, we have to do things this way and it won't hurt your bottom line because everyone else has to follow the same regulation as well! It is just the cost of doing business. If they disagree, they are more than welcome to go to prison themselves for anything that happens.
If you can't monitor critical bug notifications and can't fix or provide a compensating control, you should not be in security.
I hope all affected parties are able to sue them.
Most people work for companies with neither the data anybody would much care were stolen, nor the resources to secure it. Equifax had both, bigly.
This is indeed food for thought, and what I'm mentally chewing on is: why would you - or anyone - make such outlandish statements in a comment on HN? Are you seriously excusing them for reasons that effectively boil down to "this could have happened anywhere"? Do you really hold companies that hoard such sensitive data sets to that low a standard, and if so, why? Whyyyyyy?
I agree with his assessment, I just wish it was otherwise. Many orgs are simply lucky they have not been actively targeted by a determined attacker - they would be lambs to the slaughter.
Even in academia, where we absolutely were understaffed, insecure, and compromised, we stayed on top of the CVEs for the tools we used and did our damnedest to not fall behind. I fully reject that a group with the resources of Equifax could not have been more proactive.
I also think it's entirely understandable to crucify this company, as NOT ONLY were they lax in their job, their failure resulted in material harm for individuals who had no meaningful choice but to participate with them. I find the idea of these "Structurally mandated protection rackets" appalling enough that I certainly would hold one of them to a harsher standard than I would a typical company. With great power etc etc.
The fix is not a simply apt-get. Upgrading struts can break things and testing and verification takes time... but it's a machine hosted on the internet with troves of customer data... as such I think your being too easy on them.
A particular customer service rep needs to be able to get at most of one person's data at a given point in time. In fact, they should probably be somewhat rate-limited as to how many people's data they can look at in a given period of time. The front-end server that runs the app that serves up this data probably should not even be allowed access to the full set of data at any given point in time. Also, presumably this has to happen from a desktop computer at a call center that's at a company that contracts with Equifax, so it would be reasonable to assume those computers are VPNing to some Equifax network, not that access to all customer data from any internet address is a necessity.
That should've been a huge point of the published document, not just "we didn't patch, so it's game-over".
There's a reasonable expectation that those sorts of companies produce very resilient, fail safe software.
Credit reference agencies deal in PII. It's their main asset. It's incumbent on them to protect that data with secure coding practices, proper patching policies, pen-testing, etc. Above all else, that's their key professional obligation.
If they refuse to do this, they shouldn't be in business. I would go so far as to say that given their size and available financial assets they should be held criminally liable. There's no reasonable excuse for them not securing the data entrusted to them.
> Whatever company you work for, if you do not have regular pentests, you are no better off.
> It seems very strange to choose this one company and crucify them just because they lost your data.
This company literally has the one of the juiciest gold mines of exploitable personal data in existence. They should be crucified because standards should be higher for them than almost any other enterprise.
And unlike stolen addresses and credit card numbers (which can be changed), this genie can't be stuffed back into the bottle.
"Equifax was the victim of a hole in Apache Struts" -> Likewise.
Nothing so valuable should be safeguarded such that a single failure results in total loss. It is utterly their fault.
Why? I crucify every company that loses my data. I would imagine that most people do. This company lost everyone's data.
It's not about the security issue in particular, it's about an organization that didn't have proper security practices. This wasn't an unknown security issue, it was a reported and fixed issue.
(Also, they were using Struts, not Spring.)
Not everyone has this amount of personal data, including social security numbers, names, credit history on 140M Americans. So no, it' not "just like everybody"
> N is very small -- maybe four?
That is a ridiculously long time for a company holding the kind of data they are. "Yeah, yeah enterprise whatevs, I know". But I work in enterprise as well and we patch and roll out security updates within days. Like you said, it is mostly "apt-get upgrade" run from Chef or whatever management system they got.
> "they failed to run the equivalent of sudo apt-get upgrade on their framework."
Don't agree with that. It's like saying "The train conductor _just_ had to press the break in time. It's a simple action. Let's not overreact here..."
> machines, this is a situation that almost all of us have wound up in.
I somehow never wound up holding personal data of 140M people. And if someone told me to "hold that data", I'd say "sorry, I am not qualified, it is highly likely I'll mismanage it and it will be hacked".
> Are you sure you won't be next on the chopping block?
No it's not. Because I don't have the personal or financial data of that many people in my care.
The question on the table is whether or not Equifax could have prevented the data breach with the application of up to, oh, let's say a few tens of millions of dollars in resources (personnel, equipment, what-have-you) and merely applying common sense and industry accepted best practices. The answer seems to be: unquestionably yes. At least for this breach. And so, because that amount of money is much less than even their annual profits, Equifax has unquestionably acted negligently in that they had both the resources and the obligation to prevent the breach, but did not. There's no excuse for that.
And I 100% support holding them responsible for damages caused by that.
Netflix: Oops, we let an unauthorized user watch all videoes.
US Navy: Oops, we let an unauthorized user launch all ICMBs.
I would hold each of these parties 100% responsible for those respective damages.
> look at this rationally.
Rationally, organizations would take different security precautions depending on the consequences of a hypothetical breach.
Food for thought.
No, see, this right here is the part where you and I disagree with each other. This wasn't stupid, this was negligent.
Once you have a certain amount of customer PII, you have to act like an adult. You put all the PII behind a special interface and database and hire a well-paid team of security specialists to take care of it. There should be people whose entire job is to read about new exploits and be updating that PII system within hours, not weeks.
A good PII system should have triple-A: authentication, authorization, auditing. You should know for certain who is calling the PII system, how often, for what records. You should have automatic audits/alarms looking for clients who are suddenly increasing their call rate (or better yet, rate limit each client). Automatic searches for clients whose behaviour has changed suddenly. When someone is clearing out your PII, you should know very quickly.
Equifax did not do the adult things. They got owned, and now 150m people are at risk.
The vulnerability was in Apache Struts and has existed for 9 years: https://arstechnica.com/information-technology/2017/09/equif...
> Even if your firewall is great, you can still smuggle data out of a network using DNS alone.
That's why large enterprises have internal networks with no external access. Also why many security/network teams monitor the changes in volume as well as profile of traffic like DNS. You should be doing that anyway, because it allows trivial spotting of malware contacting CC servers.
Just to expand, there is nothing wrong with having a music degree, there are qualified, experienced people who don't hold the degree in their current field. Except in this case we start from the end, given the situation, we are assuming we are not dealing with qualified, experienced people but amateurs. So then we are looking and combing through their credential, proof of competence etc., and so far it doesn't look good.
What is the chance that these executives flee to a non-extradition country such as Russia or China for a bit, "just in case"?
Some people flee to the EU because they can make a plea against extradition based on the appalling human rights abuses in the US prisons.
I hope Lauri Love wins on that front.