Elizabeth Warren's bill would fine the next Equifax for data breach
cnet.com
cnet.com
- Securing your system (like PCI)
- Training your employees
- Disclosing a data breach in a timely way
AND if the company follows all the rules they are protected from the fines.
There is no reason why a company that does their absolute best to be secure but falls vicim to a zero-day vulnerability should be treated the same way as someone that was willfully negligent like Equifax.
If a company is willfully negligent (Equifax, Uber, and AshleyMadison are notable examples) I think a fine is not enough. Revoking their license to do business needs to be on the table as a maximum penalty in the most egregious cases. I'm talking companies that try to hide the breach from the victims, systematically underspend on security, etc.
Edit: As an aside, as someone who has done a number of startups in a CTO role. Sometimes getting the board and upper management to agree on spending money on security is like pulling teeth. A lot of startups end up getting to a 100,000 users without even thinking about security never mind putting appropriate systems in place. Penalties for neglecting security would give CTOs powerful ammunition to be able to invest in this critical area.
On the other hand, simply ensuring that the financial penalties are in line with the damage done should be enough to solve the issue. You said yourself that boards won’t agree to spend money. If they saw a huge financial downside risk they would be more likely to invest in security.
That bar may even move depending on factors like revenue, number of users, and sensitivity of data.
> On the other hand, simply ensuring that the financial penalties are in line with the damage done should be enough to solve the issue. You said yourself that boards won’t agree to spend money. If they saw a huge financial downside risk they would be more likely to invest in security.
I completely agree. Not sure if it came off correctly but that was the point of my edit at the end.
That can be part of the law.
Conveniently this is most onerous for stupid business models.
I'm leaning much more toward John Young's (Cryptome) viewpoint of information security -- smoke and mirrors. Maybe nothing is secure and it is only a question of how interested the adversary is in creating a break and then what they decide to do with the information after.
Robert Cringely has the most practical advice I've read -- keep secure communications off the internet.
I agree with a lot of the points in this post, but I think it's important to remove 'willfully' from this statement. If a company takes on this type of power and responsibility, it should not matter whether their negligence was willful.
If I pre-meditate to purposely use my car to kill someone that is a different crime than if I am driving following all the rules of the road and I don't notice the person crossing the street until it is too late.
In many countries, when you injure a pedestrian through absolutely no fault of your own (i. e. they drunkenly stumbled onto the street and you had no time to react), you (or your insurance) are still liable for damages.
Why is that? Because when you drive a car, you get all the benefits of, well, driving. Pedestrians get absolutely nothing, except the "chance" to suffer whenever they don't pay enough attention.
Note that this is civil law. If you had no chance to avoid the accident, nobody is blaming you, nor will you face criminal charges. But the pedestrian suffered damages, and cash transfers can (re-)distribute those damages to more accurately represent what would be considered "fair".
Simply knowing that you can be sued and no TOS can prevent that would be a huge improvement. It’d tell everyone that they need to think seriously about security & privacy, and the costs would push many companies to question whether they should be storing as much data as they possibly can.
And if a company decides that it can’t completely protect itself.. hey, what about not collecting so much bloody data?? Wouldn’t that be a lovely side effect? If (P.I.) data, by its very existence, became a toxic asset, to be handled only when absolutely necessary?
PS: It also simlifies the court cases as demstrating a data breach is more straightforward than demonstrating a company followed all reasonable precautions even though they failed.
The disadvantage though is that thanks to zero-day vulnerabilities it means anyone who runs a software company can get hit my lightning at any time. And quite possibly through no fault of their own.
Though I suppose there could be insurance policies for that in the same way a home contractor has insurance for if they fall off a ladder.
At the same time, sending an auditor to an office for a couple days to assess their security readiness is cheaper for the tax payers than tying up the courts if/when a large company disputes the fine.
[0] Supervision of Technology Service Providers examination booklet: https://ithandbook.ffiec.gov/it-booklets/supervision-of-tech...
To take your contractor falling off a ladder analogy, the company that built the ladder could be held partially liable for the flaw as well.
Fines aren't enough because the leadership of the company is often totally insulated from them (case in point: Equifax).
But one caveat I’d add to your point. Companies should not have a free pass for losing data that isn’t directly required for providing the service the user requested; or when storing data the user did not give them permission to acquire.
Data should be a liability not an asset.
One is a sort of punishment for what is considered a moral failure. For people there's criminal law, but when organizations "misbehave", fines are usually easier to assess rather than individual responsibilities.
That is the context in which you are concerned about fines, because it seems unjust to punish where no intent to harm (or gross negligence) existed.
But fines in this sort of civil law context also serve a different purpose: much like a carbon tax or late fees at the the video rental store, they serve to internalize negative external effects. In this light, there is no moral judgement or stigma attached to fines.
Put another way: the damage is already done when the data is lost. All that's left is to assign responsibility. "No fines" leaves all of the burden with the individuals whose data was lost, even though they are unlikely to have any power to stop such breeches. By fining the company (and possibly compensating the victims) the existing damage is only moved to the party that had at least some control over the situation.
Strict liability leads to the market actually solving the problem. It's not just that insurers, who have skin in the game, will do a better job of coming up with standards and auditing them than regulators. It's not just that the cost of insuring excessive amounts of personal information will lead to companies not storing private information unnecessarily. It's also that this cost will create demand for actual secure hardware and software. Zero day vulnerabilities are not inevitable in a world where their costs are actually internalized. We could build secure systems, if we were willing to pay for it.
We don't let car companies sell cars and then just add some fine print saying "this car might blow up and kill you even if you use it correctly and we are not responsible for that". Why do we let software companies do the same?
I don't think software warranties should be mandated by law - if that were the case, open source software would probably never have come to exist. But I agree with you that software intended to sit in important security boundaries probably mostly should be available with a warranty. Again, imposing strict liability on the company leaking the data will find this equilibrium if it is the right one. You will go to buy "cyber insurance" for the 100 million user profiles you are storing- a $10 billion possible loss for the insurer- and they will read the fine print of your software licenses!
When we are talking about stuff sold to consumers- smartphones that lose your personal information or webcams that are part of botnets- it's a little less clear. The legal system probably isn't up to holding individual webcam owners liable for an attractive nuisance, and then having them turn around and sue the manufacturers, etc. It is more practical to impose liability on the manufacturer of the product by default (unless the consumer use is negligent). But again, any such regime needs to be crafted carefully to not effectively outlaw free software, hobbyist friendly hardware, etc. Be careful what you wish for.
We need to adequately start pricing in the costs of externalised losses, and studying what actually works, otherwise nothing will get better.
Since basic risks were not addressed, Equifax (and anyone else showing this level of neglect) should be severely punished.
A lot of these people have been in the game long enough that many best practices we're invented after they stopped learning.
This is does not justify their behavior, rather it provides more context around the a potential contributing cause.
To clarify, I am not talking about a CSO at a 100 person startup. I am talking about somebody like the CSO of equifax or Boeing which should have hundreds of people reporting to them. They cannot possible know the specifics of everything they secure.
Having a C-level who knows nothing about the core practices of their domain should be treated as a liability for such an organization.
Never assume malicious action when inaction gives the same results. It's more likely that the Struts vulnerability was not addressed because it would require development time and effort for a stable, functional system and all resources were dedicated to new features. That's pretty much the default mode in any company without management emphasis to change priorities.
They left the full payload unencrypted available to all. No deep hacks necessary, basically wget.
https://motherboard.vice.com/en_us/article/ne3bv7/equifax-br...
Completely false. There's been no reputable reporting that substantiates that claim.
Key questions:
1. Does this apply to all data aggregators, or just CRAs?
2. Does it apply to government breaches, banks, individual businesses, etc?
3. What additional oversight is going to be applied by the FTC that isn't already happening as part of the vast amount of other regulations? How will it protect consumers?
Could you actually point to where the issues are rather than make such generic claims?
"Allowed"? She phrases that to make it sound like Equifax just left the front door open. In truth, they were hacked by sophisticated criminals (possibly state sponsored), who pinpointed a flaw in their security and exploited it. There was a detailed Bloomberg article that covered the breach in depth. They found that Equifax had paid top dollar for solid tools, but they were misconfigured (or misused) in such a way as to actually not be working. They found that they had good written procedures. Equifax knew about this vulnerability, and thought they had patched it. So how is any of that "allowed"?
In addition, Equifax stock took a huge dip and hasn't recovered (down 21 as of this morning). They're also going to provide features so that all consumers (whether they were potentially impacted by the breach or not) will be able to lock and unlock their credit file, for free, forever. So not only did they take a big hit in terms of stock price, they are giving away the revenue generating lock and unlock service.
> If passed into law, the bill would give the US Federal Trade Commission the authority to inspect the companies that collect vast amounts of financial data on consumers to make sure they're protecting that information.
In what way does this in any way actually help consumers? Does the FTC have some sort of magic wand to prevent breaches? Does this help out with the overall problem of identity theft? Will this add any security or confidence above and beyond the existing government and industry regulations that are already in effect?
Will her new law address any of these? https://www.identityforce.com/blog/2017-data-breaches
Maybe you haven't heard about one of the exploits, but leaving the front door open is what I would call using "admin" as both username and password. This also implies no further configuration was done past install and setup...
https://www.cnbc.com/2017/09/14/equifax-used-admin-for-the-l...
I also wanted to add that the software in question that was compromised was a free and open source solution[0], not some top-dollar security program. And it was breached by relative simple XSS attack that even may have been carried out automatically. Beyond that it could just as likely have been a script kiddie who caught wind of the vulnerability on a message board somewhere and went hunting. I wouldn't call that highly sophisticated. XSS protection is the very baseline of internet data security...
I'd also like to point to a video posted by another user upthread (willfarvar):
https://www.youtube.com/watch?v=vsMydMDi3rI
FBI's Frank Abagnale speaks to the Equifax breach at ~37m (as willfarvar says, though, the entire video/talk is great)
---
Can you document a lie they've told?
> as they've tried to mitigate the entire situation via PR already
Of course, any company would do the same. But did they lie?
> claim many users [who were affected] were not affected.
Can you back up this claim? They claim 147 million potentially affected...and you think that was under representing it?
> I also wanted to add that the software in question that was compromised was a free and open source solution[0], not some top-dollar security program.
The code in question is heavily used in the industry, from the highly respected Apache Foundation. I.E. it wasn't some college project they found on github. Many other companies were affected by this vulnerability...they just either did a better job of patching it or weren't sufficiently interesting targets to make it worth going after. Or didn't report it...
As far as the sophistication, you should read this: https://www.bloomberg.com/news/features/2017-09-29/the-equif...
Assuming you trust Bloomberg, they report that there was an initial intrusion that didn't get anywhere, but appeared to get handed off to a much more sophisticated team that did the real breach.
Re: Frank Abagnale...he's exactly right on one point. The breach was tracked back to an employee who failed to follow the procedures and left a system vulnerable. In my view, the real problem is that their procedures were brittle enough that one person failing to do their part was enough to leave them vulnerable. Not enough redundancy. Even that isn't enough for perfect security, but having multiple people required to certify something like this would greatly reduce the odds of a breach.
However, his claim of negligence is complete bunk and supposition on his part. Equifax followed their procedures...they received the vulnerability report, processed it, applied patches, and ran scans to verify. However, one employee failed to do as required, and the scans were faulty and they didn't know. How is that negligence? It's a broken process, for sure, and they didn't have the ability to detect that it had failed. But negligence would be if they knew about the vulnerability and ignored it, and it's simply not true.
Negligence in their case is evidenced in the larger picture. One isolated incident can be just a dramatically terrible mistake. When there are obvious and foolish mistakes being made when the stakes are millions of peoples' personal and irreplaceable identification, then I think negligence is a fair term.
Re: not telling users they were affected https://www.marketwatch.com/story/after-huge-data-breach-equ...
Re: continued negligence in the response https://www.wired.com/story/equifax-breach-response/
Re: signalling of Equifax's possible intentions through the fallout https://techcrunch.com/2017/09/08/psa-no-matter-what-you-wri...
Then why did you say you were "hesitant to take their word at face value"?
> Without entering through the front door, any attacker would have had a monumentally more difficult time installing any kind of back door access.
Again, read the Bloomberg article for more details...your version doesn't match the facts as reported.
> When there are obvious and foolish mistakes being made when the stakes are millions of peoples' personal and irreplaceable identification, then I think negligence is a fair term.
What "obvious and foolish mistakes"? A single failure to patch a single vulnerability? Equifax receives a vulnerability report. They do their process to apply the fix. They get the messages back from the project teams that it's done. They run the scan to verify, and it comes back green. Where's the negligence? I know the process didn't work, but that's a hindsight thing...how can you tell something like that is broken unless it breaks?
> Re: not telling users they were affected
Per the article, they weren't "not telling people" as in, withholding information. The messaging was poor, but they weren't intentionally misleading anyone.
> Re: continued negligence in the response
Incompetent, maybe. But that article doesn't reference any negligent behavior.
> Re: signalling of Equifax's possible intentions through the fallout
And idiot opinion piece with no basis in fact. It's clear that none of the B.S. predicted there has come true in the 4 months since it was written.
I agree that a federal agency barreling into this space is likely to be ineffective, but I'd rather nudge them to build policy with security experts than continue allowing every freaking company to police itself. The latter has proven to be ineffective.
There's a difference between "left the back door open for two months" and "the back door was open for two months because the person assigned to verify it was closed told everyone it was".
> If "good written procedures" weren't followed, what good is that?
How do you know they aren't being followed? How many layers are enough? If a process breaks down, what's your first signal?
> allowing every freaking company to police itself.
CRAs don't police themselves, they're audited and regulated already.
Her main regulatory creation was a whole new agency that is completely unaccountable to the people it was supposed to serve. She's the last politician I trust with these sorts of things.
Honest question: Is that her fault? She was just chosen to run it, but she wasn't responsible for the legislation that created it and its lack of accountability, or is that wrong?
I don't think Ms. Warren really understands most of the issues in finance she's often cited as a champion for, and dislike much about the CFPB, but this new effort to put dedicated personnel around setting minimum security standards and imposing civil penalties isn't too bad, as long as it doesn't indemnify the bad actors for victims seeking individual damages.
[0]https://www.scribd.com/document/368838846/Data-Breach-Preven...
Wow, so Consumer Finance Protection Bureau 2.0. Unbelievable.
Of course I would prefer legislative action so that the regulatory environment doesn't change at the whim of the executive, but when basic harm prevention seems to be a partisan issue, I see little chance of legislative action being successful.
That's a gross misunderstanding of how CRAs function. You explicitly give permission for whatever businesses you interact with to forward your credit info to a CRA, and you explicitly give permission for them to reference the data held by CRAs.
Additionally, other actors that collect information about me without my permission are advertisement and social media companies.
> other actors that collect information about me without my permission are advertisement and social media companies.
So those notices from web sites about cookie tracking, or the Terms of Use from social media companies, aren't enough to warn you about information collection? They can't collect it if you don't visit their (or affiliate) sites.
It may have been true in the past, but nowadays pretty much any reputable company has explicit terms and policies related to collection and use of personal data, and you have agreed to those policies by using their services. And non-reputable companies wouldn't care what you wanted one way or another.
This is true, but the CRA is the beneficiary of this behavior and I would be surprised if they don't encourage it. But yes, the CRAs are not solely responsible. They just benefit from the widespread practice of making housing availability contingent on credit score.
>So those notices from web sites about cookie tracking, or the Terms of Use from social media companies, aren't enough to warn you about information collection? They can't collect it if you don't visit their (or affiliate) sites.
I don't use social media (aside from here and Reddit). That doesn't stop Facebook et al from placing tracking beacons all around the web and building shadow profiles on people. Regarding the cookie notices, by the time one has been displayed you've already landed on the site that uses them so it's presumably too late to avoid.
I go to great lengths to not be tracked. I generally browse without js enabled, I block ads and third party tracking requests. I do my best to not consent to bring surveiled. But should not these things be opt-in rather than "desperately struggle and still probably fail to opt out"?
All done through agreements with the sites you do visit and which spell it out in their ToS.
> I go to great lengths to not be tracked. I generally browse without js enabled, I block ads and third party tracking requests. I do my best to not consent to bring surveiled.
So do I. I have 3 ad blockers on my browser and use a custom hosts file to deny as much of this stuff at the network level as possible.
> But should not these things be opt-in rather than "desperately struggle and still probably fail to opt out"?
I agree with this 100%.
>All done through agreements with the sites you do visit and which spell it out in their ToS.
By the time I visit their ToS, more often than not I've landed on the page with tracking beacons and the damage is done.
That last is why you need an office in the first place: for problems which are important enough to care, you need experts who are familiar with the field and aren’t working for a party with an interest in the outcome. Experts like having health insurance, paying their mortgages, etc. so you need to be able to offer them jobs, somewhere for them to sit, funding to support research and analysis, etc.
In terms more familiar to HN, your question is like asking why your company needs an IT department when you can hire consultants. I mean, yes, you could just let Gartner and Oracle tell the CEO what to do but it wouldn’t be cheaper.
No, it's not. That's how it looks to everyone who has ever been on the receiving end of a bureaucratic nightmare. I believe part of the reason the Democrats have done so poorly in the last few years is because middle class America wound up on the wrong side of Obamacare and it woke them up.
> In terms more familiar to HN, your question is like asking why your company needs an IT department when you can hire consultants.
No, it's like your company hiring an whole new, separate IT department, with minimal oversight, every time they hire a new contractor, instead of training up the existing IT team.
What's interesting to me is that the ACA never had majority favorability until repeal was legitimately on the table. And then all of a sudden people "woke...up" as you put it to the idea that their 20-something year old children could lose health insurance, or a person who had cancer years ago could be denied coverage, or that an underemployed person in Kentucky could lose their Medicaid-based health insurance.
Let's be clear: the ACA has a lot of problems. Some of these, like spiking premiums this year, are due to the actions of the current Congress and President. Some of these are due to a lack of real competition, which may have been addressed if the law had included a public option buy-in[2]. Some of these, like shitty exchange websites, are a real problem.
[1] https://www.realclearpolitics.com/epolls/other/obama_and_dem...
[2] Blame Joe Lieberman for this: https://www.publicintegrity.org/2015/02/16/16766/elimination...
Here's the page where they show all the polls used to collect this "summary"[0]. Interesting that the vast majority of them show "against" strongly winning.
The PPD poll giving +18 for ACA shows that 49% want to impeach Trump, but conspicuously doesn't ask party affiliation. That's a huge red flag of a stacked poll.
[0] https://www.realclearpolitics.com/epolls/other/obama_and_dem...
Also, best of luck with your poll unskewing. I had thought that the legitimacy of that ship had sailed all the way back in 2012. Guess not.
For one, it's the latest poll, and you're fixated on a recent change in opinion on ACA.
Secondly, an aggregate of what? Once you have bad data in the mix, especially one that skews +18 in one direction, your aggregate is skewed as well. And that aggregate has half a dozen PDP polls in it alone.
Have a nice day.
Have a good one.
He became an FBI agent and works with data breaches. So after entertainingly describing his life story he does mention the Equifax breach at the 37m mark.
He paints a very negative picture of Equifax.
Its well worth watching the whole thing, and not just skipping to his FBI Agent opinion of Equifax.
"The agencies already comply with the same rigorous data protection standards as banks," said Francis Creighton, President and CEO of the Consumer Data Industry Association, which represents Equifax as well as Experian and TransUnion.
Well, clearly it's not all that rigorous.
With data breaches, there is no undo because the asset (data) moves outside a system the breached parties control.
Increase the penalties for banks and other institutions that issue fraudulent credit or otherwise fail to properly identify and authenticate the consumers with whom they’re doing business. Simply having the details of my credit report and my Social Security number should not be enough to open a bank account in my name.
Until then, however, if companies like Equifax are going to deign to hold sensitive information on behalf of THE PUBLIC and profit of of that, they had better take responsibility for it or face consequences if they fail.
And their cases would be tossed out of court for being meritless.
I would prefer receiving a $50 check in the mail from a class action lawsuit. All this does is add more money to gov't coffers
It’s not the only way to address those problems but a regulatory agency doesn’t have any of them.