5 ms·
This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of th
by Keeeeeeeks 9y ago
This is embarrassing at this point; a credit authority printing dividends is too busy placating shareholders to even pretend to give a shit about the data of the people who _involuntarily_ have their PII stored on their platform.
Whoever files a class action should make a motion such that anyone can purge their PII from a credit authority that's experienced a public hack such that their PII was exposed, or some other sort of incentive for these too-big-to-improve companies to do their job
- rbanffy 9y ago> too-big-to-improve Love that!
- FLUX-YOU 9y ago>purge their PII from a credit authority I can't see that happening if they do any kind of offsite back up and archiving. They will purge you from the current master, say they purged you, and you'll be none-the-wiser.
- toomuchtodo 9y agoI wish someone would go Mr Robot and corrupt their offsite tape backups with the HVAC system.
- samstave 9y agoThis is a unix system! I know this!
- eicnix 9y agoThe best solution for this would be to enable similar data protection laws like the ones that will become active in 2018 in the EU. A breach of this law would cost a company 2-4% of their revenue as a fine. Seeing how these big companies operate there would be a lot of breaches.
- solomatov 9y ago>The best solution for this would be to enable similar data protection laws like the ones that will become active in 2018 in the EU. I like GDPR, but a lot of people claim it to be too draconian. We'll see how it works out in EU.
- Someone 9y agoThey could encrypt each person's data with a unique key. Then, purging a person's data would come down to deleting that key from the system and from all backups of the keys. That makes it a bit easier; the set of all keys will typically be a few orders of magnitude smaller than the data, and could be backed up using separate systems. Those systems wouldn't have to be updated often and access could be better controlled. You would still need procedures checking nobody writes out non-encrypted data (including database keys), but that's doable; a first level scan would just run strings on your raw disks. Disadvantage is that this would affect performance, especially for reporting services (a query gathering statistics over your customers would have to fetch all your customers' decryption keys) A step up would be to hand out not bare decryption keys, but pairs (decryption key, expiration time stamp) encrypted with a private key that only your database knows the matching public key of. That allows your database to detect when your applications reuse decryption keys for too long. Depending on application architecture, that pair could even be a triple (decryption key, session key, expiration time stamp), and 'encryption' of course should use a salt.
- chrsstrm 9y agoAnd in the absence of legislative action the only thing we can do in the meantime is go after Equifax's data sources and customers. I know that Citibank uses Equifax for providing FICO scores to their cardholders. Voicing your concern to banks like Citi and threatening to close your accounts if their relationship with Equifax isn't terminated can be effective if a big enough percentage of Citi's customers complain. An interesting aside, Mint announced on the 6th of September that they were updating their FICO score service to use TransUnion. They had previously used Equifax. That's either an incredible coincedence or they knew about the breach before anyone else and switched providers.
- bga 9y agoOr Equifax became unresponsive while they investigated, but didn't reveal what was happening. Related, but not via inside info about the hacks.
- otakucode 9y agoWhat legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. You can't claim negligence of following industry standard practices when there ARE no industry standard practices. The closest we have in the software field is the work done by NASA on creating legitimately safe code. But companies don't want to follow those sorts of guidelines because they make software development slow and expensive. Sure software development is the primary driver of their businesses existence no matter what industry they are in, but they feel entitled to it being cheap and fast.
- solomatov 9y ago>What legislative action could be done? Require companies whose systems have a large impact on peoples lives hire licensed, certified software engineers? There is no such thing. Require them to follow industry standard practices? There is no such thing. Create new regulations governing the manner in which business management addresses concerns raised by developers? There is no such regulatory body. Why there're standards for cars, but no standards for computer systems? I think it's possible to create them. If there're standards, it's easy to define malpractice.
- adekok 9y agoYou're surprised that large companies are incompetent? My experience has been that the main product of most companies is management politics. Actually shipping product is nearly irrelevant to everyone's daily activities. In some cases, people get punished for being competent. One company I worked with made it clear they had no interest in listening to competent people. People were promoted for their ability to suck up to management. They got promoted when the projects they managed were delayed, buggy, and generally non-functional. Any competent engineer was summarily drummed out of the company for causing trouble.
- psyc 9y agoSuddenly, I'm feeling like it's time to re-read Catch-22.
- j_s 9y agoBy Joseph Heller in 1961? https://amzn.com/dp/B0048WQDIE/ https://amzn.com/dp/B0048WQDIE/ e-book $11.99
- nerpderp83 9y agoI worked here
- orblivion 9y ago> _involuntarily_ This is probably part of the explanation.