Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed
bloomberg.com
bloomberg.com
There was one company (very well known) I know of that was breached, but their logging and general security infrastructure was so poor that they had no direct evidence that customer info was breached, so they didn't have to report the hack. They only found the intrusion due to excessive load the intruders caused on some services.
Customer info was certainly accessed (the attackers where everywhere), it's just there was no record of it as the records they kept where so few and far between.
Part of me thinks it's a pretty clever workaround to such laws.
cough cough Yahoo!
Making it worse, they actively sold this as a multi-tenant platform to be used with mutually untrusting parties.
When I met with engineering and started to explain, they started smiling and said "this is a known issue and we're going to fix it in our next version."
Quite some time later I ran across people using it in the wild and they had not passed a lot of the glaring holes. Even their newer version had a hidden input field on the edit profile page named "IsAdmin". This did exactly what you think.
They ended up having a successful exit as far as I know and I've never heard anyone speak ill of them security-wise.
Telecom is a mess. These holes are easily exploitable for direct profit. But there's so much more low-hanging fruit, I don't think people bother.
It's good practice to have a staged-disclosure procedure for leaks of this nature.
For example: your bank should be told to start fine-tuning its anti-fraud capabilities BEFORE the entire world is made aware that you can be defrauded in this particular manner.
The reason I ask that question is that it's definitely not gonna happen. But it's arguably a lot better than the situation right now where we have a few malicious actors who do have that information. If the data was completely public I feel you'd have a huge effort to fix the problem bwcahwe your neighbor can look up your credit worthiness. Yet I think the situation right now is worse because we won't have that effort to fix the problem yet 95% of the people who would have caused you problems have that data.
The Irony is their actions on remediation are almost exactly in line with the decisions made that often times lead to the incident. It's cyclical.
With often vague or only theoretical damages, it's harder to muster support for draconian consequences.
Also people can sort of understand accounting. Dollars and cents and balances are something most people can comprehend. Computer software and security breaches, on the other hand, are much more of a black box for most people. They can't intuitively understand what's sensisible and reasonable and what would constitute negligence when it comes to protecting software sytems and data, other than by relying on what other people tell them.
It would not be a bad strategy at all to leak the names of as many potential scapegoats as possible if one were avoiding accountability.
https://krebsonsecurity.com/2017/09/equifax-hackers-stole-20...
I never realized "real name elitism" existed on HN
Generally one is expected to use context clues to disseminate which meaning is most relevant to a given sample of text.
In this case they were to indicate a somewhat mocking tone in my paraphrasing.
The exact quote actually managed to be more condescending than that:
> Commentors with novelty usernames should not expect responses.
On a totally unrelated note, you sound like a wonderfully pleasant person to interact with. I am deeply saddened those of us with "novelty usernames" might miss out on that.
The size of the sells were truly negligible for all executives involved, in proportion to how many shares they have and routinely liquidate. The same argument that there were any sells at all would been made regardless of the number of shares.
A company that size will always have material non public information.
Equifax's OPSEC was horrible all along and a gigantic leak was bound to happen, so the extent and ramifications of this fairly routine breach were eeeeehhhh not considered.
> Cons for not prosecuting:
The execs did it on the same day.
Something something the people something want blood.
If you're in that position, then wouldn't you make sales regularly on scheduled dates? (say quarterly)
Otherwise theyre asking to get prosecuted, if not for this sale then the next.
Sure, doing anything out of that schedule is always a risk, and doing things on that schedule doesn't mean there isn't insider trading still happening. A successful prosecution under these equities-specific market sanctions will rely on more than that.
I guess I'll attempt to reword it yet again:
They have 10b5-1 sales, or even if we don't know we can see that they have sales on an internval.
They can have sales outside of the schedule.
Sales outside of the schedule always have the risk of scrutiny. These sales are getting scrutiny for being outside of the schedule.
That said this might absolve them of some responsibility if 5 months ago that vulnerability wasn't disclosed to major companies.