3 ms·
I cannot for the life of me fathom how you think this is okay. I've worked in far less stringent environments than I would expect from Equifax and we would neve
by 1_2__4 9y ago
I cannot for the life of me fathom how you think this is okay. I've worked in far less stringent environments than I would expect from Equifax and we would never have allowed a vulnerability like that to last a few days, let alone months.
This is indeed food for thought, and what I'm mentally chewing on is: why would you - or anyone - make such outlandish statements in a comment on HN? Are you seriously excusing them for reasons that effectively boil down to "this could have happened anywhere"? Do you really hold companies that hoard such sensitive data sets to that low a standard, and if so, why? Whyyyyyy?
- spydum 9y agoHe isn't excusing it, he's making this point this is far more common, and if you looked at any of the fortune 100, in sure you will find the same or WORSE practices. I agree with his assessment, I just wish it was otherwise. Many orgs are simply lucky they have not been actively targeted by a determined attacker - they would be lambs to the slaughter.