5 ms·
Why do you hope that? Do you want them to be liable? If it was a zero-day then they legitimately may not be at fault.
by bodz 9y ago
Why do you hope that? Do you want them to be liable?
If it was a zero-day then they legitimately may not be at fault.
- mistercow 9y agoIf it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. In either case, it's a very small amount of evidence anyway, but in that respect at least, hoping it wasn't a zero-day makes sense.
- bodz 9y ago> points away from a world where a hundred million people's private information is unavoidably vulnerable Regardless of this specific situation, we already live in this world. We all just need to get used to it.
- deleted 9y ago[deleted]
- a3n 9y agoWhich way to the frog sauna?
- bodz 9y agoI have to be honest, I have no idea what you mean. I tried googling "frog sauna" but all I got were advertisements for actual saunas for frogs. Lol ️
- grzm 9y agoI think it's an allusion to boiling frogs. https://en.wikipedia.org/wiki/Boiling_frog https://en.wikipedia.org/wiki/Boiling_frog
- nol13 9y agoSo if someone takes this data and just keeps the whole dataset exposed publicly on a tor site, is that pretty much the end of data breaches? Like, some random website: "we just got hacked, all you pii was taken, but don't worry nothing thats not already available in that public database" other than new credit card #'s it'd be basically pointless right?
- sattoshi 9y agoWell... no. Everybody on that list will change their CC and life carries on until the next breach.
- nol13 9y agowell ya thats the point, credit card breaches may still happen but those are easy to cancel, but all the PII would be permanently in the public domain.
- jklein11 9y agoThe fact that the pii existed is more systemic. We use social security numbers to verify identity and have a unique way of identify people across systems. If our current system of doing this (i.e. SSNs) are no longer reliable we will have to come up with something to replace it. If what we use to replace it is as brittle of a solution we will run into a similar problem down the road.
- sillysaurus3 9y agoIf it was not a zero-day, it means the attack was preventable, which points away from a world where a hundred million people's private information is unavoidably vulnerable. Working in the security industry quickly cures you of this illusion. It is unavoidably vulnerable in most cases. If someone wants to pop your network, they can usually find a way. The most clever code won't prevent someone from strolling in and plugging a raspi onto your network. Nobody notices an inconspicuous black box amid a pile of cables.
- hossbeast 9y agoSure, if you don't have physical security, you have no security. Goes without saying.
- sillysaurus3 9y agoUnfortunately ~nobody does. The effectiveness of red teams was one of the most surprising aspects of working in security. The most common way to break into someplace was to pose as a construction worker: http://i.imgur.com/ZjnGmZ5.png http://i.imgur.com/ZjnGmZ5.png If you're dressed as one of them, you can go wherever you want and people rarely ask questions. Another approach is to pose as an interviewee. That's how you get into the building, but beyond that you never actually talk to anyone so nobody is suspicious. People generally don't care when someone is walking around the halls dressed up in a suit. One of my coworkers was involved in dozens of red teams and he got caught a grand total of one time. Every other time he was able to acquire an IP address, take a picture of himself sitting in the exec's chair, swipe a file out of the server room, or whatever the customer wanted.
- haimez 9y agoSo, every time, he took a pic in the exec's chair, stole a file from the server room, and also did whatever he wanted? What is the 'N' factor here, because it sounds like your friend is a bold high schooler who achieved N=1,2,3(tops). Pretty boring security stuff.
- MichaelGG 9y agoI find their behaviour overall rather abhorrent and against people in general. Justice should be served, but I hope it goes very poorly for them. Sorta like one might hope something bad happens to Oracle.
- kelnos 9y agoI despise the existence of the credit reporting bureaus and would love to see one of them caught with their pants down for a breach that was entirely preventable (well, at least through the vector that was used). If they failed to patch a known vulnerability, and that caused the breach, likely they'll be on the hook for a larger payout once settlement time comes.
- phkahler 9y agoThis is exactly what I meant. These companies compile large amounts of personal financial data without peoples consent. They use SSNs for non-tac purposes, which I think is/was illegal. This ultimate cause of the breach has nothing to do with the exploit used, but rather the fact that this company and its practices exist at all. They put peoples info on a computer connected to the internet for no reason other than efficiency - profit.
- bluejekyll 9y agoForget about the zero-day for a minute. They should be liable for poor storage practices around sensitive PII. Take for example SSN. With SHA2, there is no good reason for them to be stored in plaintext. If you don't need it, don't store it. For SSN, you just need a function (SHA256+Salt) that would give you a one way mechanism of Creating an identifier that masks the original in an irreversible way. The prevalence and misuse of SSN as an identifier for people is so out of date at this point and weak. We need something different.
- bga 9y agoIf you're just hashing with SHA2 and a salt, an attacker with a run-of-the-mill GPU could crack any given hashing quite quickly. It might still take quite a bit of time to get all 143 million, but that's fine. Sell off the score in blocks of 10,000 and let the customer know they have to reverse the hashes themselves. BCrypt with lots of rounds would be best.
- bluejekyll 9y agoYes. You're correct of course. We should be treating these like passwords, except that they can't be rotated...
- maxerickson 9y agoIt is an identifier. It isn't really a problem to use it that way. The problems all come from using it for authentication.
- bluejekyll 9y agoI should have made that more clear in my statement. The thing that makes me paranoid is it's use as an authentication method by my bank, et al. With this disclosure, much of what banks and others use to authenticate my identity is now out in the open.
- bodz 9y agoThere's no evidence so far (that I've seen) that points to Equifax storing SSNs in plaintext. The initial reports so far indicate that the exploit scraped the SSNs while it was in use by other systems, and not at rest in a database. Encryption (whether they do it or not) wouldn't have saved the day here. > The prevalence and misuse of SSN as an identifier for people is so out of date at this point and weak. We need something different. I completely agree.
- evilDagmar 9y agoNo, they'll still be at fault because if you have a massive pile of highly sensitive data online, and all it takes is one vulnerability to get at it all, then your security model was awful. Was this database typically accessed with broad-sweeping queries that could snarf large amounts of it at once, or was it the sort of thing where a few specific keys were used to identify a single client record? My thinking is that it was probably the latter, and if that's the case then another layer of security should have been in place there. Stored procedures can be used to require very specific queries to access very specific records--this falls under the "prevention" category. Next, monitors should be deployed so that someone gets notified right away if some session makes a large number of successive queries to get around the restriction--this goes under the heading of "detection". These two things would have been able to prevent attackers getting the goods with just one exploit. ...yet companies regularly fail to take these kinds of simple and rational steps seriously, and then act like it was all just too hard for anyone to possibly defend against.