After Equifax breach, anger but no action in Congress
politico.com
politico.com
Like other political hot topics, this is one of those things that causes me to ask, "okay, then, how bad does it have to get before populist outrage brings about change?" Something worse happens, and this is the time, right? Nope. And so on from one event to the next.
OTOH, in this case maybe the invalidation of vast amounts of data will alone bring about changes out of necessity. There will probably be a rough patch of lawsuits, debate, and perhaps a new law or two, but perhaps it will eventually shake out something better.
We had a bill in the New York State Senate after the Equifax breach [1]. It was dead on arrival. Practically nobody called in to offer support. It was apparent that nobody's political career would be made nor broken by this bill. When it died, there was no press; nobody noticed nor cared.
[1] https://www.nysenate.gov/legislation/bills/2017/s1104/amendm...
That said, I'm not sure how much of a fix timely disclosure is. Maybe people thought it wouldn't go even remotely far enough to help a significant number of people and hence wouldn't be worth it. (I could even see it being harmful if it makes it less likely to get more serious legislation passed.)
A bit of this, a bit of that. I was excited about the bill and offered to help. When it came to selling it, however, people were more animated by Trump, affordable housing and the MTA. Despite our obsession with privacy on Hacker News, it hasn't been properly sold to the public.
> I'm not sure how much of a fix timely disclosure is
It was to allow the Attorney General to investigate these crimes. Right now, there is no disclosure requirement. Unless the company reports its breach and co-operates with state Attorneys General, they basically can't be held accountable at the state level. So, naturally, they refuse to co-operate.
I'm still betting (small) on that happening.
That's a ludicrous thought. They were the victims of a crime, not the criminals. Should Target have been bankrupted? Or Home Depot?
This is in no way similar to Target or HD, other than data were taken. The whole system upon which Equifax was built relied on a semi-secret number that cannot be changed. Those numbers, or at least the majority of them, are out in the open. There was a certain degree of trust that the person sitting across from you at the auto dealer finance desk was who they say they were, and that the report stating that they're good for a loan was accurate. That was not 100% true for a number of years, and it's potentially wildly inaccurate now.
IOW, Equifax's sloppy work resulted in a broken system from where I sit. If you're thinking I'm wishing bankruptcy upon Equifax, well, I didn't write that, sorry. But if the shaky foundation upon which your business model rests collapses, I would expect severe financial penalties. But, hell, Moody's is still in business.
You mean "which the credit industry was built"...not Equifax. Equifax is just one of the big 3 CRAs. Singling out Equifax in this context is taking a very narrow view.
Does the breach call for some punitive response? Definitely. Does it justify destroying a $14B company? No. That's an overly emotional, witch-hunting type of response.
HN of all places should be sympathetic to what happened to Equifax; they neglected to update a framework which had a vulnerability granting full remote code execution. That's game over from an info sec standpoint, and how many developers here can state, with 100% confidence, that every library and every framework and piece of application code in their own work is totally bulletproof and will never fall victim to something similar?
The breach should be used by everyone as a lesson, and as I stated earlier Equifax should receive some punitive action (arguably already delivered by the hit to their stock price and the public floggings from the congressional hearings). But saying that Equifax should be bankrupted by it, or that the executives or developers should be thrown in jail? Be careful what you wish for. Today Equifax, tomorrow you.
In most serious breaches, there is a certain amount of "well, you have to be careful who you give your information to..." even though it's not the victims fault. This factor is not present in the Equifax situation. Equifax is allowed to hold and market a product based on data of individuals who never gave consent, but has no responsibility to protect that data or repercussions when they fail.
Arguably this breach has put the final nail in the coffin for using SSN's as secure identifiers. Granted, it was a horrible and mostly-already-broken system to begin with. But I think that this flawed system was still worth in excess of $14B - and Equifax's negligence effectively destroyed that value. I agree bankrupting Equifax would be heavy-handed, but it would be nice to at least see some punitive action that would discourage such negligence in the future and provide an economic disincentive to possessing vast quantities of private data.
We’ve all made computer mistakes like this, but the stakes are different. If I forget to update a framework and as a result a bunch of cat pictures leak, that’s not a big deal. If I do the exact same thing and leak important private info with financial consequences for nearly every American, that’s a much bigger deal. They data they collected needed to be stored in a bulletproof fashion. You could argue that this is impossible, but that just means the data should not have been collected at all.
The calls to destroy the company seem pretty reasonable to me. This is a classic case of an externality. Equifax cost a shitload of people a bunch of money, and they’re bearing very little of the cost. Arguably they’re actually profiting from it by selling fraud protection services.
The only question to me is: just how much did they cost the American people? Whatever it is, they should bear the entire cost. And I bet that cost is more than the company is worth.
But you're probably not talking about me, as I'm the one pissed off that those calls made money, not thinking they've been punished. It should have hit $93 and stayed there.
Your argument is wise to consider the "let he who is without sin" perspective, but I don't find it that compelling. They had a hoard of valuable information which they carelessly stored and they paid essentially zero consequences. If I had to choose between this world, and the world where Equifax was just liquidated with the proceeds going to people affected, I'd prefer the latter. "Won't somebody think of the shareholders?" I have, but I've also contemplated the tens of millions harmed by their incompetence.
Why should I be sympathetic to them, especially after how they handled it? And especially given that they make loads of money off MY DATA, and want to turn around and have the gall to charge me to see it, to make sure it's accurate?
1) Store all this information, unencrypted
2) They were told of the vulnerability in March and had 2 months to update the software.
3) Afterwards, set up a broken website with a DV certificate to accept SSN numbers.
4) The website, even though was a vulnerability disclosure, tried to _sell_ an Equifax identity monitoring package.
5) Redirect your own customers to a phishing website set up by a white hat hacker
6) Allow employees to have usernames/pws like 'admin/admin' on edge servers
The circumstances that led to the vulnerability, and the actions that Equifax took afterwards absolutely warrant outrage. And this is not even taking into account the original point - this is a pattern of incompetence and failure - but to add to the fire, Equifax was a company that was tasked with storing highly sensitive personal data for millions of Americans and did not take the appropriate security steps to do so; in fact, they ignored even the most basic security measures. They should have had at least bank-level security with such a responsibility. There is no excuse.
Pricing this into the service from the beginning might well cause disruption to a number of industries, but that isn't automatically a bad thing. And "innovation" that consists of involuntarily inflicting risk and suffering and ruin on third parties is perhaps not the kind of "innovation" we need -- one might just as easily argue that laws against involuntary human medical experimentation "hamper innovation".
Whelp... this is who is deciding what gets done in pretty much all cases.
But, in the case of IT security, their experience and expertise is, at best, not helpful.
"keeping customer information secure" is not a binary. Most companies that are breached don't know about it until their dat hits the black market. Yahoo! revised their data brach estimates upwards half a dozen times from 100million+ to ~3billion+. The plaintiffs would have to affirmatively prove that a breach happened to the defendant when most defendants don't even know that it happened.
It is even harder to contractually enforce when the victim claims it was a nation-state-actor/APT since no company could hold out against a determined APT indefinitely.
I'm hopeful that cybersecurity insurance policies will move the needle towards accountability and increased prevention (insurance policies will require good-faith efforts at security policies+procedures+tools+employee actions or they won't pay out).
If it were possible for all of the affected to individually sue Equifax, many of them already would have.
But the US civil-legal system requires "standing", which in turn requires proof of "damages". The sad fact is that loss of sensitive information is not quantifiable as "damages" for this purpose, even though that same information is worth well north of $millions when the FEC looks at the same kind of information transaction in election campaigns.
"The markets" that fiscal conservatives love to talk about don't work when our civil system doesn't recognize that there is value and a market there.
If the data breach had resulted in masses of data being traded on the black market, the Equifax breach may have ended in prosecutions and massive lawsuits. Because it didn't, it likely won't end in much.
Hell, not even the banks, retailers, and ID security services that did business with Equifax bothered to make a big deal about cancelling their contracts+relationships. The sad fact is that there's a tiny pool of companies with this data and cutting off one company gives the other players (who aren't much better at securing their networks) massive leverage.
Credit firm customers aren't the victims.
The generalized GOP party line is that this kind of thing is better left to private enterprise and the federal government shouldn't spend time and money coming up with some sort of identification strategy.
So what business has the motivation to spend that kind of effort? Google or Facebook?
It's kind of a perfect storm of sorts, there isn't any pressure to fix it, anywhere. The public has even lost interest in it, for the most part.
I'm not sure how that happens. Equifax basically exposed everyone in the US with any credit to identity theft and scams. If those thefts trickle out bit by bit over a few years, there will be no single, shocking crime wave, and nothing will happen. It doesn't take genius-level criminals to avoid creating a big enough incident.
On the other hand, I would be curious what would happen if some public-minded hacker stole ~150m people's data from one of the other two CRAs, then publicly released 538 specific records...
Then there are countless other credit analytics companies hoarding all kinds of other specialized data. It's scary to think about.
As a PSA: check out the list [1] of credit reporting companies that the CFPB puts out. It has the names and contact info for most and you can get copies of your full reports from them upon request (most are either required or do so voluntarily). It's a lot of effort to hit all of them but pretty eye opening and, frankly crazy, to see just how much is tracked. There are databases for how often, and where, you return items to stores/businesses as one example.
[1](http://files.consumerfinance.gov/f/201604_cfpb_list-of-consu...) List Of Consumer Reporting Companies
Congress needs to do 3 things
1. Find away to limit and prohibit SSN from being used for Identity.
2. Give People Ownership over their PII, end the concept of "who collects it owns it"
3. Make companies liable for damages when they lose control over PII that is collected
Congress does NOT, should not, and likely can not create rules and regulations to govern data storage, security, etc. They should stop trying as that is not a problem they need to solve nor is it a problem that should be "fixed" in law
This would result in a twenty-four hour recession. The U.S. banking system can be shut down [1] while records are analyzed and fraudulent transactions reversed. Presumably a digital hack would result in digital dollars being stolen and subsequently frozen. Whatever couldn't be recovered would probably be, in large part and at least at the retail level, re-imbursed with new money.
There is a very small window to essentially pass legislation unchecked and that hasn’t been easy with a 52-48 (with a tie breaker) majority in the Senate. We saw several failed attempts at repealing Obamacare.
What’s more that majority is about to shrink to 51-49.
My point here is the GOP currently has no time for anything bipartisan. That doesn’t mean they’ll address this of course. But it’s just not as important as the donor class agenda is right now.
Once Doug Jones is seated and we start to approach the midterms expect to see more unifying issues instead of, say, hugely unpopular tax bills for billionaires.
- Black card number stolen? Card frozen.
- FDIC insured account attempted to be flushed. Banks flag and or fraud protected.
You should read up on the havoc that is caused with stolen identity. I'm not talking stolen credit cards, more like unknown judgements taken out against you and wage (in extreme cases, wage garnishments).
[0]https://www.forbes.com/sites/thomasbrewster/2017/12/19/120m-...
Source?
Search for section heading "California as precedent?"
My memory was imperfect, the real story is even more direct: The data breach was the Stephen Teal Data Center, which houses payroll for state employees, including legislators and staff.
Sounds comparable to the June 2015 OPM breach [1], which leaked 4 million federal background check records. The root of the problem is in something other than connecting the powerful to the problem. (The Equifax breach almost certainly inconvenienced powerful people at least as much as most average Joes.)
[1] https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
a.k.a.: how much evidence is there of actual harm having resulted from the breach?
- the 1 free year of identity protection to expire
- if there's a surge, it will definitely be on the radar, it will be more publicized and more and more people will take defensive actions (like buying extended identity protection and/or freezing credit). As we can see, it kinda blew over.
I mean, that's what I'd do if I'd be in the 'stolen data' business.