7 ms·
> When asked by multiple lawmakers why Equifax set up this separate site, Smith said the company's main domain was not architected to process the enormous traff
by dtran 9y ago
> When asked by multiple lawmakers why Equifax set up this separate site, Smith said the company's main domain was not architected to process the enormous traffic the company knew would come its way after the announcement. In all, Smith said, the independent breach-response site has had 400 million consumer visits, which would have crumpled the main site.
Apparently they've never heard of subdomains, static pages, reverse proxies, and <insert many other solutions anyone on HN could come up with off the top of their heads>?
- rconti 9y agoRight. I think it's code for "I think domain means website, and our technical folks said our existing corp site didn't have the capacity, so we told them to setup a 'completely separate site'".
- brandnewlow 9y agoAlso maybe "Our marketing folks want all the angry links to point to a separate domain we don't care aboout vs. our main web site"
- mrkurt 9y agoThis is PR recommendation #1 when you get breached.
- mikekij 9y ago^ This. SEO basically.
- KGIII 9y agoIt strikes me more as a move suggested by a reputation management company, though they may have in-house specialists. While usually, and intentionally, behind the scenes, reputation management companies are often involved in things whee there is massive public outcry.
- austenallred 9y agoYa, that solution alone says a lot about the technical decision-making taking place. Especially given that random numbers input to the site returned that data had been compromised.
- akg_67 9y agoMost probably their marketing and legal team came up with the idea. Once the outcry blows over turn off the site and all incoming external links become dead. After a while general public will not remember and wouldn’t associate their main site with this incident through search. Legal might have encouraged to have two fully independent sites. I will not be surprised two sites belong to two separate legal entities. Just a speculation on my part considering how US corporate behave.
- wmccullough 9y agoWithout looking it up, I’ll throw my chips on the table that they offshore the majority of their IT.
- mavelikara 9y agoOffshore or outsource?
- greedy_buffer 9y agoMaybe. The separate domain might be explained by lack of trust in their PR company though. See Krebs' article: https://krebsonsecurity.com/2017/09/equifax-breach-response-turns-dumpster-fire/ https://krebsonsecurity.com/2017/09/equifax-breach-response-...
- drieddust 9y agoThat's just Horseshit. I have worked on both sides of the table and incompetence is equally widespread. However, vendors are not as bad as they seems to appear and employees are not as good as they seems to appear. Most of the contracts nowadays have a penalty clause and a stated Service Level Agreements (SLA) around performing the vulnerability scan and closing the GAP within a stipulated time frame. Outsourcing companies might not be innovative but they don't like to lose money on failing SLAs. Coming back to the issue of incompetence. I have often seen so called innovator of the just taking the credit for the work done by Vendor. The way typical scenario rolls out is this. Senior management of of the company will throw a challenge to the senior management of Vendor. After a few discussions middle management of will assign the responsibility to their lowest level employees. After a lot of hard work when solution is in sight, all communication channels will be closed. A few weeks later solution will be presented to their own management while keeping the vendor completely out of loop as if vendor was completely useless and they did all the hard work. Vendor will be presented as mindless robot who can just execute the instruction. Hell I have seen employees not even having the courtesy even the reword our solutions. Incentives of employees are aligned with making the vendor look less effective or they themselves will be replaced at some point by their own higher management. I think its not their fault. It is just the environment where painting the vendor in positive color will be detrimental to employee's own job.
- wglb 9y agoSeems to me to be dead simple. One dns entry for equifax.com, another pointing off to different hardware for equisecuritybreach.equifax.com. Nothing fancy at all. Make the page have a different look and feel.
- speedplane 9y agoA ten-year-old can do it on godaddy in ten minutes.
- Mouse47 9y agoNot me :( I'm just a .NET developer, I have no idea what my code runs on.
- nameless912 9y agoAssuming you're serious, get on that my dude! All the best developers I know have a solid mind for ops; operation of your application should inform its design.
- smsm42 9y agoThat seems to be indication that decision process there is as broken as security process. Either they did not have a professional that could explain the management why the claim above is baloney and what are the solutions to make it work, or that professional wasn't consulted, or his opinion was dismissed by the management. In any case, the symphony of fail continues.
- 0xbear 9y agoOn the positive side, their chief security officer can compose one heck of a musical composition.
- ComodoHacker 9y ago>the company's main domain was not architected to process the enormous traffic I understand all the sarcasm expressed here, but this actually may be true if they run their own DNS service. Subdomain isn't a solution in this case, but separate domain is.
- Xylakant 9y agoI fail to see why DNS would be an issue. Set a sufficiently large TTL and you should see almost no queries hit your DNS servers once intermediate caches have seen the domain.
- ComodoHacker 9y agoWith this amount of traffic you have to load-balance, so you can't just set large TTL.
- azinman2 9y agoBut load balancing also applies to their new domain as well. Why would you need a separate hostname?
- Xylakant 9y agoLook, you could just set the new subdomain as a cname with a large TTL and then handle that a-record via a different provider if you really need to. You could also choose to delegate the whole subdomain. Also, load-balancing via multiple a-records does not at all depend on the TTL. DNS is really the easiest part to handle here. Internal policy might prevent delegation, but that’s not a technical problem.
- ComodoHacker 9y agoHow can I handle a subdomain with a different provider while handling the whole zone myself? I'm not an expert in DNS, so really curious.
- benmmurphy 9y agofrom a security point of view it does kind of make sense to have non-trusted content hosted under a separate domain. so if they were using a third party to host the breach page it may have been risky to have it hosted under the .equifax.com domain. this is why you have .github.io and googleusercontent domains, etc. though, probably the risk from confusing users is worse than the risk from the third party playing silly games with cookies in this case.