4 ms·
No amount of governmental regulations can solve the current date breach trends. Even government's own intel agencies got hacked too. No organization is immune t
by devy 9y ago
No amount of governmental regulations can solve the current date breach trends. Even government's own intel agencies got hacked too. No organization is immune to data breaches. It's a matter of time and effort.
A lot of us here are engineers and coders. It's our responsibility to design better architecture, security conscious protocols and write securer softwares. And it's up to all of us (regardless which country you are in) to voice up and resist the idea of weakening encryption or allowing backdoors and instead advocate for adopting better and more securer encryptions to safeguard private and sensitive personal information.
- orf 9y agoSure, in a fantasy land. If you where to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. The very fact that all this data was accessed from their public site is very troubling. What's the chances this is a basic SQL injection issue? What's the chances they didn't invest in security at all?
- beepboopbeep 9y agoHigh. And they won't be the only agency. I guarantee you we'll hear from the other 2 in the next month or so. Because people aren't held criminally responsible for the security of user data, so why give a shit?
- jjeaff 9y agoMy guess is they paid an 3rd party bs service to "scan" their site for vulnerabilities.
- devy 9y ago> If you where (sic) to hold the management criminally responsible for their lack of investment in IT, security etc you might see increased investment. What makes you think lack of investment in IT & security is the main reason they get hacked? Vice versa, NSA has virtually unlimited (let's just say unlimited means tens of billion dollars) budget invested in IT and security. They have the top resources there too. Do they immune from data breaches and being hacked? The answer is a big NO!
- bsenftner 9y agoCertainly a lack of mental investment. The NSA and these credit agencies are not a comparison, as their jobs are quite different. If nothing else, the NSA has to be connected to public networks to do their covert operations. Not so with a "credit rating agency". They should not be on a public network at all. Before the Internet, they were not, they were on private leased lines.
- devy 9y agoYou missed the point. I am arguing that no amount of investment is big enough to make data breaches go away. Even the top intel agency with top budget and top resources can't avoid breaches, what else would you expect a corporation? However this is not an excuse for Equifax to not put more focus and investment on their security.
- orf 9y ago> I am arguing that no amount of investment is big enough to make data breaches go away. Sure, nothing is totally secure against a dedicated, motivated attacker with unlimited resources. Thankfully those are few and far between. Based on that Equifax has said that this doesn't seem to be the case.
- danblick 9y agoYour argument that credit rating agencies shouldn't be on the internet is really terrible. People pay credit rating agencies to retrieve their credit reports, get credit scores, and open disputes, and the best way to do all that is online.
- philjohn 9y agoYeah, but then they realised they could monetise it by selling your own data back to you with easy, constant, access to it via the web.
- RickS 9y agoCorrect me if I'm wrong, but the NSA leaks have all been the result of internal employees leaking outward, rather than outside people reaching inward where they shouldn't. That's a meaningful distinction, IMO. They call for two completely different types of defense.
- snom380 9y agoSure it's our job to do that. The job still gets easier when you have the law backing you up. An excellent example is how many companies are in panic mode right now to get GDPR compliant before next year. There's a lot of security engineers and developers that finally get the budgets and time they've asked for to improve customer privacy, because the potential fallout of non-compliance is too big to ignore.
- Taek 9y agoI think it's a fruitless effort to try and secure all of the data in the world. Our data is lying in too many places, the databases holding them are too complex, as another user stated, a breach is really just about money and time. Our systems are too complex to merely increase security standards. I think we can significantly improve the situation though with increased data collection laws, and then also more cryptography. Equifax shouldn't have all that data in the first place. A lot of the reasons that companies need data (besides machine learning) can be covered with cryptographic arguments that exclude the data itself. For example, cryptography exists that would allow me to use my driver's license to prove to you that I am over 21, without ever actually showing you my real birthday or name. You could be 100% convinced that I both have a valid ID and that ID indicates that I am over 21 without learning anything more than those two facts. If you can do things like that, you can make it illegal for companies to hold more sensitive information. If there's a big data breach that loses sensitive information, the company at fault can be charged for illegal data collection. I know it's a big step from the data driven world we currently live in, but I think it's the only way to avoid a scenario where pretty much all details of every person's life (including politicians, secret agents, military figures) are public knowledge. We're just collecting far too much data, putting it in far too many places, and it's technologically infeasible to protect all of that.
- craftyguy 9y agoYou hit the nail on the head. Real progress can only be made by severely limiting the amount of data being collected.
- bsenftner 9y ago"No amount of governmental regulations can solve the current date breach trends." I'm sorry, but that is just flat out false. That type of thinking is just bizarre to me. It would make a gargantuan difference. Hold executives personally accountable, with whistle blower laws protecting the developers who identify weak security. It would change the freaking world over night.
- moomin 9y agoForget regulation. Pass laws and just fine them. A lot. So much it's a threat to the company's existence. Pretty sure it'll turn out to be a solvable problem. If it isn't a solvable problem then we need to start talking about getting this data off the Internet.
- mulmen 9y agoWhat is regulation if not law?
- mulmen 9y agoRegulation is absolutely capable of reducing the damage done by these types of attacks and incentivizing companies to make the necessary investments. Nothing will ever be 100% secure but that is no reason to just give up on trying. We tried letting the free market do the right thing and it failed, this is the reason the government exists.
- daveheq 9y agoEquifax had engineers and coders building their hackable site, at the direction of Equifax, within the scope of the law (unless we discover they broke security regulations). Having regulations with suitable punishments gives the company an incentive to build the site securely, and it would have been skin flecks off their back to do it, but their profit motive and lack of legal incentive meant they didn't care to. If you're really so terrified of the government that you're against security regulations for the website of one of the largest credit card information collectors in America, then you deserved to be hacked too.
- SonicSoul 9y agotrue. I once worked at a bank and we used a 3rd party data warehouse web solution to get started with a new business. 6 months into it, i noticed that I could access cross customer information by modifying local javascript variables. When I brought this up to my manager he told me to patch this up asap. which i did, using MD5, because i was a jr engineer back then and didn't know any better (and apparently neither did my manager, nor the creators of that data warehouse) my point being, without guidelines, or regulations, or some sort of security rating standard, managers will continue to make these mistakes.
- cr0sh 9y ago> No amount of governmental regulations can solve the current date breach trends. I think there's a few things that could be done: 1. Invalidate all SSN numbers. 2. Force people to get a new ID card; make it like the smart-card passport card (or make people get such a card). That becomes your ID and number. 3. Getting that card requires you to be present physically for fingerprinting. Put the fingerprint data on the card, and no where else. 4. Make regulations that only allow for loans to be done in person - no more mailings, nothing online - if you want credit, you have to show up in person. 5. To prove who you are: Fingerprint, your card (with picture - and fingerprint data on the card), plus your pin number. Essentially chip and pin identification, with a fingerprint scan (and maybe a face scan too). 6. Make it so if you want to do online transactions - or any transaction for that matter - you must provide all of this. Basically, at home, a card reader that can read the chip, allow you to enter the pin, scan your fingerprint and face, and if all of that matches what's on the card, then an "acknowledgement" is sent. Essentially the above would implement a 3-factor auth. I am not saying the above is perfect (I am absolutely certain I have screwed something up there - but the basic idea is what I am trying to convey), but we essentially have to do a clean break away from all current ID and credit/loan/payment systems - and move to a system that introduces a TON of friction. Physical Presence (Something you are) Physical Token (Something you have) PIN (Something you know) And all the data about "who you are" (face scan, fingerprint) stored on the card (hashed of course) only, no where else. Basically - the card, your presence, and your knowledge all have to be present, and the card's processor authenticates you. And these factors need to be presented each and every time you do a transaction of any sort involving money or identification. And no online or by-mail signup for credit. That should be done in physical form only. Finally - allow for at-will changes of the PIN, and yearly a forced change of the PIN. The problem with the above, though, is many-fold. It would be extremely costly - for everyone. It is also (seems in a way) draconian. But something of the above nature would need to be done, post haste, if we wanted this to go away. And basically not allow any kind of storage of credit information or whatnot by -any- entity (and I am not sure how that would even work or if it could). Maybe all they have is a hash value and your name, and the card can generate that hash value as "authentication"/"identity" - but you have to have everything there (you, card, pin), and only the card holds the information, and only generates a hash. I dunno - but again, this is the idea. I'll leave the details to people smarter than I on these things. I don't expect something like this to be ever implemented, though. One would think this breach would do it, but it won't.
- ehsankia 9y agoYou can't stop breaches, but there are minimum things you can do that help. 1. Collect the minimum amount of information you actually need 2. Hash and salt the data you store 3. Tell the people the truth about what happened to their data within a reasonable time These are all things that can potentially be enforced.
- homo_lupus 9y agoTotally agree - 2016 was a record year in terms of breaches and it keeps going. The problem lies in that security and efficiency have been historically at odds with each other. This is what inspired us to work on bringing a novel data security technology from the University of Harvard to the market: www.f-lock.ca . Essentially we are allowing for querying functionality, while achieving homomorphic-level of security. Would love to connect with any people here who share the same vision!