Equifax IT staff had to rerun hackers' queries to work out what was nicked
theregister.co.uk
theregister.co.uk
There are so many things wrong in that sentence but my most glaring question is: why on earth was she even receiving the alerts? That's so far below her level. So, there's more here than just the cert issue. There's also just a complete disregard for a secure mindset from the person that is supposed to be setting that mindset in the culture, along with what sounds like micro-managing to a state of no-managing.
The executive got confused and suspicious when the security researcher offered to send additional data and talked about sending that data securely via PGP (it seems like he simply didn't know what the request for a PGP key... even meant).
https://arstechnica.com/information-technology/2018/04/paner...
It would seem a lot of Equifax executives are happy to act on their own in spite of their own ignorance.
I know a handful of folks in security, they run into complete morons in the security industry all the time. It's scary how wildly variable the talent in the industry is at all levels.
To some extent that talent variability is everywhere, but the sheer volume of people are so clueless that they could be described as a liability in some situations is surprisingly high when it comes to security. I know security folks who have changed jobs simply because they didn't want to be associated with someone who took over at their employer. Reputation among the folks who know seems to be a big deal to many of them.
1. Dude contacts you.
2. You fail to work with him / or just don't.
3. It becomes public and you look like idiots.
That pattern is so established that every security executive should know you want to avoid that... but nope, some run headlong into it.
I'm no security dude at all, and I can recognize that pattern just from reading the news. What on earth is an executive reading if they have no idea?
That said, for every legitimate security researcher, there are dozens of people who are blowhards. Bug bounty programs, for example, are stuffed full of "[CRITICAL][ACCOUNT TAKEOVER] EMERGENCY VULNERABILITY"... which is actually some skiddie reporting someone being able to XSS themselves.
On the outside, you mostly just see the ones that go bad. On the inside, any given report is unlikely to be nearly as severe as it's claimed to be.
The unfortunate thing about the Panara Bread deal was any dude could have just pulled up Postman and hit the API and seen the results / issue in a couple seconds + however long it takes Postman to start on their computer.
They didn't even try, they could have rule out "crazy researcher" in seconds.
There's also no guarantee that if they did have the Splunk alerts enabled, that they would have caught anything. In one instance I can think of, having Splunk alerts enabled did more harm than good because it meant SOC staff were busy chasing down hundreds of false alerts (aka the "noise" in "too noisy") and missed real threats. With the alerts off, the staff could use other more reliable sources of threat notifications and catch more of the real threats.
Unless you have a big enough staff, or have Splunk (and your monitoring team) tuned well enough to actually effectively sort through the alerts, they truly well can just be "too noisy".
At some point, the size of your staff doesn't really matter, unless it's at roughly number of alerts / 2. Now not only you have the alerting noise, but you also have the added noise of the big intra-team communication. Cleaning up those alerts needs to be first priority.
Not to mention, usually such a barrage of alerts means they are very poorly designed.
I mean, that might take you a day, maybe a week to catch the edge cases, and then it’s not a problem any more...
In my experiences though, there’s no time to become an expert anymore
You get it set up, then a PM or manager with no clue redirects us to the next priority. Meanwhile the new monitoring tool just hangs out being underutilized at $20k/mo
Not to say all PMs or managers are clueless, but there are more clueless ones out there than not. They are noise generators themselves.
Or, IMO worse, the sycophant coders who concern themselves with their own personal metrics, release dumpster fire after dumpster fire. And us in devops and secops are fighting their idiocy all day, not training tools to catch intruders.
I’ve worked with far too many people who epitomize that meme of Captain Kirk where he can’t hear you over how awesome he is
Most days, it is not incorrect.
This feels a bit like saying a stopped clock tells the correct time twice a day.
Turning off the alerts doesn't cause a problem unless there was something worth alerting about that day.
Our CEO likes to claim it benefits us because then they don't have to do big layoffs during downturns.
That really makes no sense. The engineers should be the ones determining which ones to adjust and which to suppress. Middle managers are already too far removed from the productive chain to even make the determination if an alert is false or not, let alone C-level.
This is assuming the security team was big enough to have that many layers to create such a disconnect...
Splunk (ES or not) is not a magic bullet. It generates a lot of bullshit to justify its expense.
Finding the signal in the noise is easy when you know what the signature of the largest data breach in history was supposed to look like. What exactly does this prove?
> Why on earth was she even receiving the alerts? That's so far below her level.
Knowing the C-levels there, they likely wanted earlier warning of emerging incidents-- EFX and their subsidiaries had been dealing with a steady stream of incidents (some public, some not) for a while before the big one. Krebs covered some of them.
I'm reminded of the Target breach.
¯\_(ツ)_/¯
I'm seriously considering that on the next massive data breach of a public traded company I'm gonna buy some stock in the onset. Even though it feels like betting against my own principles it just seems like a too good of an opportunity to miss out on...
I've moved on. It's more important to focus on election security and physical security at this point. Infosec is dead. Five years ago Bruce Schneier wrote a book called "Carry On" now he has one called "Click Here to Kill Everybody".
Just five years.
We're in a technological growth feedback function and we're unable to predict it.
I struggle with being _comfortable_ with that idea, but I don't have a problem believing the technical accuracy of it.
The argument is that even if everybody has access to all information, only a small group is able to exploit that access effectively.
So, you still end up with a small group abusing their access to the information. You should therefore aim for privacy of sensitive information.
Technically, this is not taking advantage of any public information. It is just capturing images of things happening in public. Anyone could set up a camera and capture license plates as they drive through an intersection.
So is it totally fine for a police force to scan license plates at every intersection?
The question is complicated, because the effect on people changes when you do something that is not worrisome on a small scale in an automated way at a large scale. When you add in that the people doing it have a large amount of power over people and it changes it even more.
I’d imagine it would be relatively easy to figure out where someone works and/or lives and just go find them.
Correlating across multiple public databases might make things even easier.
But I don’t think this is the point of the argument. The point is that those in power can gain more benefit from the information than the general population.
Let’s say all votes in elections become public. That information is more useful to a powerful political party than to the public at large, or a small unfunded group. If you don’t want that information abused, the argument goes, you should make sure it’s kept private.
-- Yonatan Zunger, chief architect, Google+
Published in 1998, I think it's probably still the most fascinating work on privacy of the post-internet age.
More fun fictional explorations of the subject can be found in his novels Kiln People and Earth.
I asked them what protections they took against hacking, and they told me that nobody would be interested in what they do, so they didn't have to spend any money on protecting themselves.
https://www.businessinsider.com/hacker-us-nukes-report-2016-...
A counter-example is something like Stuxnet; that likely leapt an air gap, but it was exquisitely targeted for that scenario. I'd worry about this as a nuclear component manufacturer.
An ancient piece of air-gaped hardware is pretty bulletproof. I bet the NSA would have more trouble hacking it than a fully up to date install of <modern OS> that is on the Internet.
It's very possible the biggest threat vector is leaving the door unlocked.
[0] Which, why should we? The world has moles.
Anything with a network port was plugged into the lan, which was plugged into the free router that came with the business broadband package.
Which was also the only firewall and it was still on factory defaults other than the wireless password.
As far as I can tell this is more or less standard business practice in the small to medium enterprise sector here, which is to say, the vast majority of specialist engineering companies in the UK.
Inadvertent data breaches are inevitable.
The very best you could possibly do is access logs and auditing. Which of your customers do any kind of auditing?
I'm advocating Translucent Database techniques, where patient data is encrypted at the field and row (document) level. Much like a salted password file.
System level encryption still means the admins can still see the data. Therefore, breaches remain inevitable.
Translucent Databases http://a.co/d/5855TYO http://wayner.org/node/46
Think of how password databases don't actually store passwords. Instead they (should) be storing salted and hashed passwords.
---
Please see my other comment about plaintext demographic data vs using unique identifiers.
Your conclusion is correct.
Medical records cannot be encrypted so long as demographic data must be stored in plaintext. Otherwise how would we do record matching (linking) across heterogenous systems?
The fix is to use universal identifiers. Once you moot the record matching problem, you can use translucent database techniques to anonymize patient data.
I don't expect the USA to adopt an official centralized universal identifier for people any time soon. And none of the 3rd party solutions (NSA, LexisNexus, ChoicePoint, Facebook, etc) are acceptable, for various reasons.
I mean, sure it has a cost, some of this stuff is new, but to say "cannot be encrypted"... that's where the fun is- working out how to do it.
Obviously, some admins/sres still need to have full access to the key store, but that can be a very small group, as compared to a situation where "every Gmail engineer can read every user's email".
Edit: on reading the summary blurb from the "translucent databases" book link that @specialist posted, what I described above is very much along those lines.
Everyone user on that site (99% male) was exposed as a complete chump -- it's still a functioning business ...
To me it says economic performance isn't everything, and I like that idea.
quick google: https://splinternews.com/ashley-madison-comes-clean-about-al...
The data is public now -- AM were blackmailed and didn't pay -- I guess you can take a sample of the email addresses and compare with public profiles that match the emails. There were virtually no women -- in fact they were so paranoid the men would realize there weren't any women to have extra marital affairs with they had -- bots -- that flirted now and again just to keep the men paying.
Plenty of reporting was done on it after the breach. I recall saying to people that this would be a good example of a breach that would destroy a company by exposing that it's value proposition was nothing. I guess I was very wrong.
I'm reminded of the entire "robot boyfriend/girlfriend" genre of TV/Movies/Comics from Japan/Korea, plus the "dating simulator" genre of video games. These are more fantasy-fulfillment, though.
I honestly think it would be a net good for society to have simulators/bots that teach people how to have real, healthy relationships with other humans. (There are anecdoates about kids with autism who became more verbal once they started talking to Siri or the Google Assistant, for example.) But I feel like working on or using such tools would probably be as stigmatized as sex toys in the near/medium term.
Also, their target audience is nominally married people. So either these people have a fetish for cheating (weird, but not my problem), or they already are in relationships of some sort of another. One would hope that a bit couldn’t teach them anything new at that point.
Or maybe the bots are so good they should just sell those as a service? Why bother chatting with a real woman when the bot experience is better? As I say this, why isn't it a thing already? Chatbot hookers. It has to be a thing already. The interactive experience for a fraction of the price. Or do camgirls set the price floor too low to make this viable?
It seems like our NLP AIs should be advanced enough to make a pretty compelling chatbots by now. People were fooled by Eliza 40 years ago. A lot of porn is pretty formulaic too, so getting the common case right shouldn't be that hard.
They paid some fines equivalent to what they make in profit every 13 hours. That's it. Nothing else.
If you're running a large profitable company why should you care about security at all? Why should you care about the rule of law at all? There is no accountability, there is no culpability, nobody will ever get in trouble.
I hate both Bank of America and Well's Fargo with a passion and the outcome of 2008 didn't dissuade my disgust at them. Unfortunately both hold loans from me that I did not initially originate with them.
I've started using Chase and Cap One online but they have zero branches in my entire city...
Of course, you can use checks, but sometimes you need hard cash (e.g., buying a used car).
I use "cashier's checks" [1] to buy used cars, since that still offers more security and convenience (of not handling physically bulky bundles of currency).
A trick I learned from reading sites about how to buy at real estate auctions (where the final price can't be known up front) is to use multiple checks made out to oneself, in varying amounts. The ones needed for payment can be endorsed over to the seller, and the remainder can be re-deposited.
My credit union will send me an effecitvely unlimited number of these through the mail, if they're requested through the automated system and each for a at least some (reasonable) minimum amount.
Still, your point holds. If you need it in a hurry, a physical branch is required.
[1] check drawn on the financial institution, not my personal account
Buy call options, that way if it doesn't go your way you're not out as much (in theory, anyway). Worked for me with Equifax and United Airlines, as two examples. Didn't work so well buying puts on Kodak when they announced crypto-whatever; market stayed irrational longer than the life of my contract.
Keeping in mind that the next Equifax might be the one that finally gets put against the wall.
I.e buying calls at 50% IV when you only expect a 30% move before expiry is... suboptimal.
In other words, there's no substitute for truly knowing what you're doing when trading options. (Learned this the hard way, AMA)
Options are far less forgiving if you're wrong on timing.
I mean, if there's fundamental problems, it eventually has to reflect in the stock price... right?
Please?
From a business perspective, poor IT security doesn't have to be a fundamental problem. Occasionally beating up your customers may be fine, and being voted as worst company in America isn't nessesarily that bad either.
Are there fines high enough to impact business? Are you on the receiving end of new legislation because of the event? Is the market both capable and willing to punish you? Depressingly often the answer to all of those is "no".
unless everyone's doing the same thing and it's already priced in the moment the news goes public.
That's why, regardless of how large a company scandal is, you can make a pretty good bet on the company surviving and recovering easily from the scandal, because the government will protect it/issue a tiny fine to save some face. In this case, Congress literally passed a law to save Equifax from private lawsuits. Absolute insanity. If this isn't a sign of a corrupt government, I don't know what is.
It's a very sad state of affairs that will likely get much worse before it starts getting better.
As far as "Congress literally passed a law to save Equifax from private lawsuits", what they did was part of the larger sweep of allowing companies to force arbitration on consumers. It was unrelated to the breach.
Considering equifax is one of 3 monopolistic credit reporting agencies, you can be sure they won't go out of business. So you buy the dips.
Same thing with tesla. Same thing any established legit stock of a legit company. In a major bull market you buy the dips as long as the music is playing. But once the music stops, you don't want to be dancing.
Same thing with major bear markets. Short the bumps.
It'd just make sense to me that, during an investigation, one would replay what the attackers did to get a good understanding of the results. This just seems like responsible investigation.
(The flipside would instead be claiming that X was compromised, and not being able to honestly answer questions as to whether one retraced the attacker's steps to provide assurance.)
https://www.defcon.org/images/defcon-20/dc-20-presentations/...
How do you record what was accessed by a query? Record the results of every query run somewhere? Imagine the resulting data volume explosion you would endure. Instead, you maintain transaction logs or database snapshots so you can approximate database state, and you record the queries that are run. thats a more efficient means, and lets you handle DR, compliance, and investigative needs together.
This doesn't shout amateur hour to me directly, it seems more kicking a dead horse while its down, but that doesn't mean it isn't amateur hour or a complete company wide failure to prioritize security and secrecy of customer data at Equifax.
I'm not trying to defend them, just stating this sounds somewhat misleading and sensationalized.
I haven't seen any proof that Equifax operates in any other way. I am not attempting to be rude, only stating fact.
Do you work for Equifax?
Can you share that proof?
https://www.consumer.ftc.gov/blog/2017/09/equifax-data-breac...
> If you have a credit report, there’s a good chance that you’re one of the 143 million American consumers whose sensitive personal information was exposed in a data breach at Equifax, one of the nation’s three major credit reporting agencies.
> Here are the facts, according to Equifax. The breach lasted from mid-May through July. The hackers accessed people’s names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers. They also stole credit card numbers for about 209,000 people and dispute documents with personal identifying information for about 182,000 people. And they grabbed personal information of people in the UK and Canada too.
Sensitive personal and financial data of half of American adults, as well as UK and Canadian citizens. For 90 days. If that isn't proof, I don't know what is.
I am familiar with systems that do, and do not believe it to be an unreasonable ask depending on GRC [1] requirements. Storage is cheap, compression effective.
[1] https://en.wikipedia.org/wiki/Governance,_risk_management,_a...
The last thing you want is PII or other regulated date sitting in splunk in fact each large organization that handles such data will have systems to ensure that this does not happen as the regulatory requirement is simple - do not log sensitive data there are tons of both client side and server side plugins and tools for common logging frameworks and log aggregators that search and delete sensitive data or sanitize it before it being logged completely and usually you run a combination of both.
On the storage/performance side since you need to keep access logs sometimes for years if you store query results you’ll need storage 1000’s and 1000’s of times the size of your DB to store those logs this isn’t feasible.
What you log is often the query how many result did it return the user and or app that run the query.
Record systems must be able to represent the exact EHR presented to a query e.g. to check if there was a human error like some one missreading the record.
This is achieved by keeping record versions and a record history this isn’t achieved by having system logs and audit trails of queries returned.
Essentially your EHR system would work like git you’ll be able to query the same commit as the original query but it doesn’t mean that your database audit trail would record any parts of the electronic health record that is simply not allowed.
The other approach, of being able to replay a historical query described in a log while disallowing the private content in the logs allows the audit logs to be stored in a way that can be biased for better storage durability, without quite the same recursive audit nightmare. The logs are much smaller and can be easily replicated and archived, without quite the same level of risk from exposure of log content. Not to say those other logs are not also worth protecting, but there are different ways to balance the risks and costs...
I have encountered very few (not saying it's good, just that's how it is) companies with detailed database query+results logging that was stored for long enough, in any usable way...
We deeply apologise for any worry and inconvenience this criminal activity has caused. For your reassurance, we’re offering you 12 months of free credit and identity monitoring services, provided by Experian, one of the UK’s leading Credit Reference agencies.
Your free ProtectMyID membership...
That said, how do you seriously prevent such a thing from eventually happening? In this case it was their systems that were compromised but it could have easily been a downstream user or similar that had enough direct access. I’m curious to know what, if any technical solutions could be possible?
I’d never take a tech job protecting such a thing. The only way I could think would be to have some very trusted people manually reviewing all access to the primary data store, and even that probably wouldn’t be enough. Miss one unauthorized query and you’re toast.
The entire system of social security numbers is flawed by design from a security perspective and there in lies the problem.
They detected the traffic after the tls inspection box was fixed, that was the box that deteced it not the point of entry from what I understand. Regardless, TLS inspection has it's place (this is why you can't have end-to-end cryto in a corporate environment).
From my experience, most bigcorps do IT like it's still 2009. There is so much architectural bloat,bureaucracy and unseen system complexity,it reduces security controls to mere cosmetic theatrics.
It's like having a 200ft tall,50ft thick iron wall around your castle with 100k foot soldiers armed with the best weapons and training. The problem is that your soldiers(IT staff) can't act fast due to bureaucracy and half of the duties are someone else's problem due to over-segregation of duties. Your fancy wall(security solutions and controls) is neat but there are holes wide enough to fit ten people all over it.
In the end the enemy is complexity. You can't solve that by adding more security vendors,solutions and staff which is exactly what everyone seems to be doing.
On the rare case that something does blow up badly enough that executives must leave, they are still almost permanently cemented at their tier. So they just migrate to another poorly run large company to focus on their own short term gain.
Applying logic to this scenario doesn't work. It's really about balancing cost-benefits. Since the costs to being an idiot are very low once you reach a certain level, the downsides can be completely forgotten in pursuit of the upsides.
Any beyond that, "NextGen AV would have caught this" is the original premise. Nextgen tools were not needed. All they had to do was patch a well known Vulnerability within a period of MONTHS.
You can buy the fancy tools. If you can't do the basics, they are worthless.
The fancy tools are not a onse size fits all solution just like patching and goof security hygeine isn't.
https://www.politico.com/story/2017/10/03/equifax-irs-fraud-...
And Equifax is the is same incompetent company providing identification services for healthcare:
http://www.specialtycreditreports.com/equifax-contract-healt...
Nor did it prevent 18F from awarding a similar multi-million dollar contract to Equifax for login.gov:
https://federalnewsradio.com/reporters-notebook-jason-miller...
There is no incentive for Equifax to take security seriously.
The amount of surface area a large organization needs to always protect its just too large, we can just assume at some point all that info will be taken.
https://krebsonsecurity.com/2018/09/in-a-few-days-credit-fre...
Thought I should point out a major error right there in the title.
Not to bring politics into this, but there's a variant of capitalism that runs rampant in developed economies that is based almost exclusively on short term gain.
Equifax, like so many other companies, illustrates this story in painful detail - especially for those who work there.
There are so many executive poor behaviors that go on, affection not just their employees but their customers and beyond, that you might think by now there would be more attention paid to this. But the people who should be paying attention are quite like the executives who are overly focused on short term gain.