13 ms·
Equifax CEO to Congress: Not Sure We Are Encrypting Data
- crankylinuxuser 9y agoSo, has the data been actually leaked, or do you still have to pony up a load of BTC to see this?
- mrguyorama 9y agoI don't know which is worse: That Equifax is straight up lying about their infrastructure to hide malpractice, or that they don't even know
- sova 9y agoEncrypt your secrets in plaintext, the hackers will never see it coming
- nobodyorother 9y agoI just use double-ROT-13 as my TPM, that way I can invoke the DMCA too!
- colejohnson66 9y agoWhy not 2ROT13? http://www.pruefziffernberechnung.de/Originaldokumente/2rot13.pdf http://www.pruefziffernberechnung.de/Originaldokumente/2rot1...
- porfirium 9y agoPeople responsible for data protection in Equifax know perfectly well how the data is stored[]. The CEO, evidently, does not. No news here, just a headline to provoke outrage. [] Yes, "no protection" is also a way of storing data.
- ryandrake 9y agoYou'd think that when you're the CEO of a company going off to talk to Congress about your company's recent data security problem, you might, I dunno... bone up on a few pieces of information about how your own company does security? Crazy thought, I know.
- mrguyorama 9y agomaybe he realized playing dumb was safer
- leggomylibro 9y ago"Honestly, Senator, does it really matter at this point? The data is all out there now anyways, you'd may as well just let us carry on unless you want to give us a 9-figure contract to update our own infrastructure." ...Is what I can only imagine is being said when the cameras are off.
- craftyguy 9y agoWell didn't the IRS hire equifax right after the breach was exposed publicly?
- colejohnson66 9y agoThey eventually canceled[0], but yes. [0]: https://arstechnica.com/tech-policy/2017/10/after-second-bungle-irs-suspends-equifaxs-taxpayer-identity-contract/ https://arstechnica.com/tech-policy/2017/10/after-second-bun...
- janesvilleseo 9y agoIs there any way for me to get my information removed from Equifax? Do I need to contact all of my line item creditors and ask them to remove references to Equifax?
- username223 9y ago> Is there any way for me to get my information removed from Equifax? No. Pay cash or get tracked.
- caio1982 9y agoTracking is different than having your score data stored somewhere. Do you have a source for your "no" by the way? I'm genuinely curious.
- username223 9y agoI don't have a source, but you are the subject of Equifax's business, not a participant, so you have very little say. They scrape public data, and buy data from credit card issuers, store "loyalty" programs, etc. For the little you can do, see here: https://en.wikipedia.org/wiki/Credit_reporting_agency#United_States https://en.wikipedia.org/wiki/Credit_reporting_agency#United... Note that there are all sorts of unregulated ways in which companies (e.g. Facebook) use CRA data.
- kevin_thibedeau 9y agoAll of your consumer activity is sold to data brokers. All of your financial transactions involving credit instruments is sold to data brokers. They then package your data into a profile and sell it to marketers who want to target different demographic slices and compare against competitors. Most people don't have a listing in any phone books these days yet you can type in a name and get credible hits from whitepages.com. Where do you think they get that data on names and where people live when you've never had a business relationship with them?
- astura 9y agoThe "source" is 99.99% of financial-y things you do use data brokers, if not Equifax specifically. Got a bank account? You're in ChexSystem and/or Early Warning. Ever had a car loan? Credit card? Student loan? Mortgage? You're in TransUnion, Equifax, and Experian, plus more. Got a job at a large company? Your more likely than not to be in The Work Number. Ever return an item to the store? You're probably in The Retail Equation. Ever have car insurance, renter's insurance, and/or home owner's insurance? You're in LexusNexis. It's virtually impossible, unless you live on a homestead completely off the grid, to avoid these data brokers knowing things about you.
- deleted 9y ago[deleted]
- swalsh 9y agoNot a lawyer, curious if this would be a violation of https://www.law.cornell.edu/uscode/text/15/6801 https://www.law.cornell.edu/uscode/text/15/6801 Equifax themselves are not a financial institution, but as a vendor of one, would it not apply to them too?
- leggomylibro 9y agoDoesn't matter; realistically, laws don't apply to them. (Also not a lawyer)
- moltar 9y ago:facepalm:
- TylerE 9y agoJust give them the corporate death penalty all ready.
- cdolan 9y agoIt may be appropriate, but that is such a rare tool to have used, you could argue that it should be avoided at all costs. Watching the government unravel companies just strikes me as dangerous. That said, I find these credit agencies to be absurd, and need to either disappear or 100% change their business.
- ouid 9y ago>you could argue that it should be avoided at all costs ok, argue this.
- fasteddie 9y agoBecause at some point along the spectrum, the truly bad, "don't deserve to exist" companies eventually turns into the government and party in power picking winners and losers. Depending on the party, this could be anyone from Goldman Sachs to Monsanto to the Washington Post, to Peabody Energy (coal). Normalizing the corporate death penalty starts the ball rolling towards this end.
- kelnos 9y agoI don't buy slippery-slope arguments as a general rule. The tool (corporate charter revocation) exists for a reason, and should be used if that reason is met. Sure, we must be constantly vigilant to ensure the tool isn't used for evil or with bias, but that's true of anything that can be used for good or bad.
- ouid 9y agoIt's pursued in the judicial system. Our judiciary has been, in the past, fairly non-partisan.
- 9y ago
- orangepenguin 9y agoCan anyone give a summary or point me to another article (not paywalled) with similar information? I'm very interested, but don't have a WSJ subscription.
- ng-user 9y agoI second this
- bonestamp2 9y agoNon-Paywall version http://archive.is/ikG4d http://archive.is/ikG4d Source: u/neurotech1 https://news.ycombinator.com/item?id=15672691 https://news.ycombinator.com/item?id=15672691
- vladsanchez 9y agoThis is infuriating to say the least!!! >:-( Bunch of Bullshitters!!! Who's supposed to oversight these IDIOTS?
- sctb 9y agoCould you please take another look at the guidelines and not post like this on Hacker News? https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- plandis 9y agoThis guy needs to be held personally responsible. But he won’t be and that makes me extremely mad. It sucks that the rich and wealthy can be as morally bankrupt as they want without any/many consequences.
- malux85 9y agoThank you. Understanding enough encryption to know how to protect your company data would take about 1 day of learning, every CEO should know this, no excuses. I dont expect them to be able to debate cipher strengths or argue key length, but I do expect them to know about Machine-To-Machine communication, Data at rest, One-way encryption and what it takes to be HIPAA compliant etc, it's their job to know this, and it's NOT HARD. I makes me mad too.
- jnwatson 9y agoEquifax doesn't store medical data, so HIPAA doesn't apply. Here's the thing: short of some California disclosure laws, it isn't clear that Equifax broke any laws, or even any contracts. They don't have any particular duty to protect the data they have about you, other than protecting their own IP. Equifax is a clearing house for information that people say about you. Look, if I follow you around, reporting all your movements, write it down, and then my notes about you get posted on the internet, what law did I break? (Equifax used to report "his marital troubles, jobs, school history, childhood, sex life, and political activities", so it isn't that far of a stretch). Given that perspective, it makes sense that they would protect the data as much as any data vendor would. Certainly they didn't predict the PR backlash such a failure would cause and should have factored that in.
- Silhouette 9y agoThey don't have any particular duty to protect the data they have about you, other than protecting their own IP. They certainly do in much of the civilised world. The US is almost as far behind the norm in the modern world when it comes to privacy safeguards as it is in its banking and financial infrastructure.
- neurotech1 9y agoNon-Paywall version http://archive.is/ikG4d http://archive.is/ikG4d
- pogue 9y agoThanks for this. Also, for future reference, can you just paste wsj article URLs into archive.is and it will go out and pull the non paywalled article? Or does archive.is get the cached page from your browser or something?
- tptacek 9y agoEncryption wouldn't have mattered here. To a pretty good first approximation, none of the "encryption" done at scale at any Fortune 500 company in the US is more than a speed bump for attackers. Unless you're using moon math --- nobody is --- enterprise backend encryption is hamstrung by the fact that you're keeping the data because automated business processes need to use it, which means automated systems need to decrypt it.
- sova 9y agoYou mean because the data is used in a readable form at some point or another, a compromise would have resulted either way? Can't say I'm sold, my friend.
- tptacek 9y agoYes: because the point of encryption is to protect you from a compromise in your server (that's what happened at Equifax), but for the server to be able to use the data, it has to have have some means of getting plaintext access to it. Once you've lost your server to an attacker, you've lost control of that mechanism as well. This is a problem even with HSM designs; in real-world systems, HSMs usually just present an oracle interface to data. The hope is that with sufficient monitoring, you can use the oracle to buy time for defenders to detect a compromise before all your data is exfiltrated. I think most penetration testers have the experience of owning up a server and going on the brief treasure hunt for the static key stored somewhere on the filesystem.
- dredmorbius 9y agoWhat is "HSM" in this context? Among probable hits, "hierarchical storage management" and "hardware security module".
- tptacek 9y agoHardware security module.
- 9y ago
- jdavis703 9y agoWell I heard from the FBI that only criminals encrypt data using these fancy counting machine things. So it seems like Equifax may have actually done the right thing here. /sarcasm> On a serious note, we really need to make encryption a part of high school mathematics. What teenager doesn't want to write secret messages? When I took an intro to security course in college we spent a couple of classes building a very elementary understanding of how encryption works with plenty of hands on examples (using laughably insecure algorithms, but still enough to get the points across). I think most students found it the most interesting part of the course since most everything else was more about security policy (a MBA could've probably easily taken the course successfully).
- Balgair 9y agoTaking a chance of derailing the thread here, sorry: SO taught HS freshmen in physics (close, but still). I'd say we need to make math a part of HS mathematics. ~60% of the kids can't do algebra in any way. Really. Trying to make encryption a part of it is essentially useless. I hear from time to time that a 'basic-adulting' course would be great to have had. HA! You think mortgage interest rates and basic car maintenance would be learned? Most HS students in the US can barely keep from snaping their genitals at each other during class. Find me a cell-phone jammer that the FCC will approve of for under $200 and EVERY teacher in the US will buy five that very same day. You'd make billions.
- tlrobinson 9y agoBusiness idea: Faraday cage classroom kits.
- icebraining 9y agoThen some kid has a medical emergency, people take 5m extra to call an ambulance due to having to go outside or find a landline, and the school gets sued.
- Balgair 9y ago
- ineedasername 9y agoAt this point I think there is literally nothing about Equifax incompetence that would surprise me. I mean nothing. They could reveal tomorrow that their data center fire protection protocols mandate the use of printed backups, feeding them to the flames with hopes the god of data destruction would be appeased and leave their servers alone. I would not be surprised. Nor would I be surprised if the paper backups were only available as printouts on toilet paper, 1000 miles away, in the CEO's office. No, my reaction would be, "sounds about right for them, though I guess it's +1 point for effort on keeping any backups at all"
- jve 9y agoI would like to quote PostgreSQL Experts (this applies to all DBs): FULL DISK ENCRYPTION IS USELESS. [1] FDE protects against… • … theft of the media. • That’s it. • That is about 0.00000002% of the actual intrusions that you have to worry about. • Easy rule: If psql can read it in cleartext, it’s not secure. • (It’s a great idea for laptops, of course.) And then it recommends: "Always encrypt specific columns, not entire database or disk" However encrypt your backups. I think it is fairly sensible. [1] Securing PostgreSQL [PDF], Page 31 : http://thebuild.com/presentations/pgconfeu-2016-securing-postgresql.pdf http://thebuild.com/presentations/pgconfeu-2016-securing-pos...
- deleted 9y ago[deleted]
- markarichards 9y agoIf encryption is enriched with appropriate identity, authorisation and authentication systems then... Encryption at network level is a must. Corporate routers/firewalls have been very vulnerable before and the risk of grabbing everything is a lot easier if you've comprised the network. Encryption at rest is a must, as at some point you need to replace those disks and it's a lot easier if you can be cavalier with the handling afterwards because you know it is unreadable. Encryption at application level (object encryption and between services) is a must. Which means if a service is hacked or you dump the dB you may not be able to read any of it or only those records accessed whilst the hack happens. You replicate access control patterns, like in a secure building... These may come down to one or more common denominators (can you trust the security receptionist), but better that than the whole chain is vulnerable... You then only have one set of alarms, logs, metrics, etc to keep an eye on and to test very thoroughly. In the physical world: for security scenarios we have very strict procedures with locks, boxes, safes, multiple security door/gate entry systems, multiple participants and signatures involved in every action, etc to mitigate internal and external error, failure or attack - all of these can have an electronic information system equivalent and we should start designing security in web systems with these ideas in mind when it as significant as Equifax.
- deleted 9y ago[deleted]