Apparently they've never heard of subdomains, static pages, reverse proxies, and <insert many other solutions anyone on HN could come up with off the top of their heads>?
Apparently they've never heard of subdomains, static pages, reverse proxies, and <insert many other solutions anyone on HN could come up with off the top of their heads>?
Most of the contracts nowadays have a penalty clause and a stated Service Level Agreements (SLA) around performing the vulnerability scan and closing the GAP within a stipulated time frame. Outsourcing companies might not be innovative but they don't like to lose money on failing SLAs.
Coming back to the issue of incompetence. I have often seen so called innovator of the just taking the credit for the work done by Vendor.
The way typical scenario rolls out is this. Senior management of of the company will throw a challenge to the senior management of Vendor. After a few discussions middle management of will assign the responsibility to their lowest level employees. After a lot of hard work when solution is in sight, all communication channels will be closed.
A few weeks later solution will be presented to their own management while keeping the vendor completely out of loop as if vendor was completely useless and they did all the hard work. Vendor will be presented as mindless robot who can just execute the instruction. Hell I have seen employees not even having the courtesy even the reword our solutions.
Incentives of employees are aligned with making the vendor look less effective or they themselves will be replaced at some point by their own higher management. I think its not their fault. It is just the environment where painting the vendor in positive color will be detrimental to employee's own job.
There is no incentive to say either good things or bad things about a Vendor, the incentive is to keep the focus on the internal people that were involved, because recognizing internal employees is critical for morale and general team cohesion. Recognizing a Vendor's effort could potentially backfire and lead to bad blood internally (happens with consultants all the time) and is not really a priority because the engagement is based on a negotiated contract that is primarily driven by financial or expertise reasons, not the human elements.
The fact is, the Vendor is the one that should be worried about the morale of their own employees. The Vendor's management should be praising the good work of the employees, and if there is blatant disrespect coming down from the Company, it is their job to either address it or at least justify to appease their rank and file.
I was just calling out the passive aggressive parent comment.
If there was a vendor involved - Equifax would have already jumped on that fact and blamed the vendor. They would have already played the oh-we-had-a-bad-vendor-and-fired-them-immediately game by now.
As an analogy, lending your car to a friend which turns out to have faulty brakes is negligent. But lending it to him when your mechanic told you the brakes don't work is probably grossly negligent, and will often have the the same repercussions as if you cut the brakes yourself.
Some of the best infosec people I know have completely irrelevant degrees.
That said, I'm not trying to make excuses for Equifax. From what we know the head of infosec there was not qualified to do the job.
Especially given that random numbers input to the site returned that data had been compromised.
I understand all the sarcasm expressed here, but this actually may be true if they run their own DNS service. Subdomain isn't a solution in this case, but separate domain is.
I'm just a .NET developer, I have no idea what my code runs on.