Since basic risks were not addressed, Equifax (and anyone else showing this level of neglect) should be severely punished.
Since basic risks were not addressed, Equifax (and anyone else showing this level of neglect) should be severely punished.
A lot of these people have been in the game long enough that many best practices we're invented after they stopped learning.
This is does not justify their behavior, rather it provides more context around the a potential contributing cause.
To clarify, I am not talking about a CSO at a 100 person startup. I am talking about somebody like the CSO of equifax or Boeing which should have hundreds of people reporting to them. They cannot possible know the specifics of everything they secure.
Having a C-level who knows nothing about the core practices of their domain should be treated as a liability for such an organization.
They left the full payload unencrypted available to all. No deep hacks necessary, basically wget.
https://motherboard.vice.com/en_us/article/ne3bv7/equifax-br...
Never assume malicious action when inaction gives the same results. It's more likely that the Struts vulnerability was not addressed because it would require development time and effort for a stable, functional system and all resources were dedicated to new features. That's pretty much the default mode in any company without management emphasis to change priorities.
Completely false. There's been no reputable reporting that substantiates that claim.