4 ms·
Noticed this on Monday. After registering for fraud alert, they send an email that has link to http://www.equifax.com/fcra http://www.equifax.com/fcra for free
by rlvesco7 9y ago
Noticed this on Monday. After registering for fraud alert, they send an email that has link to http://www.equifax.com/fcra http://www.equifax.com/fcra for free credit report. This was getting hijacked. But not if you used https:// https://
- Matt3o12_ 9y agoWhy would they send you to a http at all if they already have https. This just seems like complete incompetence. It’s not like they have an excuse like their ad networks don’t work with https.
- froindt 9y agoSomeone in marketing probably didn't know that it mattered. Same with the head person who approved the email. But don't worry, they'll have an engineer approve it next time as well!
- RainaRelanah 9y agoBut there are protections against this, such as HSTS. I would expect someone with as much sensitive information as Equifax to have HSTS + HPKP pinned into the major browsers. Their server should never even receive an HTTP request. It's just unrivaled incompetence.
- discreditable 9y agoHSTS doesn't help if it's your first visit to the site. To work around that they'd need to get into a preload list.
- andygambles 9y agoWhich is easy if you set preload header.
- tonyztan 9y agoThis. The technology (HSTS, HPKP, Subresource Integrity, upgrade-insecure-requests) is there; sites that need it just don't seem to use it.
- Matt3o12_ 9y agoNormally, people in marketing don’t write URLs by hand. They copy them and check that they look nice or have a generator make them for them. So, how did they copy an http url instead of https because they website should have redirected them to https before processing the request (and I just hope that their internal network isn’t compromised).
- BearGoesChirp 9y agoI know of companies with typos in their links that they email. These typos lead to scam sites. I've contacted them and they haven't yet fixed it. There needs to be a serious re-evaluation of the costs associated with failing such basic security measures like using https and just making sure you send people the correct link. Right now it isn't even a slap on the wrist.
- reaperducer 9y agoProbably because security is handled by the IT department, and email communication is handled by the much less tech-savvy Communications department.
- tyingq 9y agoThe specific js that was hijacked is here: https://aa.econsumer.equifax.com/aad/uib/js/fireclick.js https://aa.econsumer.equifax.com/aad/uib/js/fireclick.js That page pulls it in. Edit: maybe a red herring. Sure looks shady though.
- Sujan 9y ago<!-- Fireclick Web Analytics - COPYRIGHT 1999-2005 ...
- g051051 9y agoSo was it Equifax that was hacked, or Fireclick?
- tyingq 9y agoEquifax. That url is Equifax controlled. It just mentions fireclick in a comment. Click the url for the js and you'll see that it does a document.write to inject a script that's an akamai cached copy from an obscure .cc domain hosted file...this one: https://a248.e.akamai.net/f/248/5462/3h/hints.netflame.cc/service/script/www.annualcreditreport.com https://a248.e.akamai.net/f/248/5462/3h/hints.netflame.cc/se...
- ryanlol 9y agoThis obscure .cc domain pretty obviously belongs (or used to belong, they let it lapse in 2016 and it was re-registered) to Fireclick.
- tyingq 9y agoHmm. Perhaps not what I thought. Looks hacked and shady, but perhaps this isn't it.
- g051051 9y agoYeah, looks like a compromised ad/stats provider. That would also explain the intermittent nature of the bad download. I'd hope that the article gets updated with the facts...other companies might be vulnerable to this as well.
- jbeales 9y agoIf you don't want to pull out your phone, throw Chrome into Responsive Design mode and you'll get the same results.
- jbeales 9y agoLooks like they just took the page down as I was poking around trying to figure out where the redirect(s) came from. Edit: Of course the error message is truthful: >The Equifax.com website and Equifax Member Center are experiencing unusually high volumes due to responses to the recently announced Cybersecurity Incident. We are working diligently to better serve you, and apologize for any inconvenience this may cause. We appreciate your patience during this time and ask that you check back with us soon. /s