8 ms·
Yeah. I mean, at what point does this level of neglect become criminal?
by jakeywankenobi 8y ago
Yeah. I mean, at what point does this level of neglect become criminal?
- MichaelApproved 8y agoIn the US? No time soon. The party in power is cutting regulations, not adding them. The customer has to watch their own back. It seems simple. The free market will kill incompetent companies, right? Customers see data breaches and stop doing business with them. Sounds good in theory but realistically, customers don't have time to do the research required for a completely free market to self regulate.
- emodendroket 8y agoIt's not clear how I, an individual consumer, even choose to avoid doing business with Equifax.
- bluGill 8y agoYou could make sure you put on all loan applications that they will not check Equifax. Probably they won't even know how to handle that though and will either reject you, or ignore it.
- dv_dt 8y agoDon't do business with them is a bogus missive, but you could lock your credit with all the agencies and only unlock the agencies you care to do business with when requested. But that often makes things difficult and not all users of that data will have an account with an alternative provider. (nor is the locked access the only product for which your data is offered...)
- FilterSweep 8y agoIt has less to do with research, even. Equifax, like many Fortune-N companies, has a heavily funded sales and PR team working actively against your individual research. Should you, as an individual, apply to a company or attempt to buy a product that has been “sold” the Equifax product suite, you’re still beholden to Equifax services(or leave without the job or house). You’re effectively stuck, unless you have the resources(time/money) to look for employers or products that stay away from Equifax.
- InitialLastName 8y ago> Should you, as an individual, apply to a company or attempt to buy a product that has been “sold” the Equifax product suite, you’re still beholden to Equifax services(or leave without the job or house). Worse, there's pretty much no way to tell to which companies and products this applies. This isn't some fast food restaurant poisoning its customers. None of Equifax's "customers" got screwed by their data leak, only the targets of their "product" caught the ramifications.
- monksy 8y ago> parties in power We haven't had a lot of politicians that have been pro-human/worker/consumer rights in a while. We got a consumer regulatory agency. But when did you see them push back against actual troublemakers.
- givinguflac 8y agoThe consumer protection agency in the US was making great strides in pushing back against many bad players, including predatory lenders. Then the republicans gutted and defunded it, ending many investigations and siding with the scum feeding off the poor.
- komali2 8y agoClassic strategy, by the way. Defund, then point to it and say "see, it doesn't work!"
- deleted 8y ago[deleted]
- tunap 8y agoAnd then jump on board? I always knew Timmy was just like Robin Hood... only different. https://www.cbsnews.com/news/private-equity-firms-are-the-new-predatory-lenders-report/ https://www.cbsnews.com/news/private-equity-firms-are-the-ne... Note to self: one flavor of Kool Aid is good, the other flavor is bad.
- MichaelApproved 8y ago> parties in power Sounds like the usual "both parties are the same" nonsense. I saw them push back all the time. They recovered billions for consumers. The success of the agency is written about in many publications. Read up on it before putting it down. One party enacted consumer protections and another party is working to rip it apart. There is a clear difference between the two. Here's an example article highlighting the success of the agency and the Republican desire to end it http://fortune.com/2017/01/27/donald-trump-cfpb-consumer-protection-financial-bureau-elizabeth-warren/ http://fortune.com/2017/01/27/donald-trump-cfpb-consumer-pro...
- ams6110 8y agoWe don't need regulations, necessarily. If people have been harmed, they can sue for damages.
- givinguflac 8y agoYeah that $500 from Equifax will definitely fix broad systemic issues affecting the whole of society. Good call!
- Buttercode 8y agoGood luck suing Equifax because you couldn't buy a home with a mortgage because Equifax had a record of you having a "low credit score" using data they collected on you that you didn't consent to. The data Equifax collects on you is both damaging and non-consensual.
- ams6110 8y agoAssuming the data collected are not in error, you mostly did consent to it. Read the fine print of any lease, loan, or other credit agreement. They almost all say they will report payment history (particularly late or non-payment) to credit bureaus.
- reaperducer 8y agoThey almost all say they will report payment history (particularly late or non-payment) to credit bureaus. If that was the only data reported to credit bureaus, that would be great. But "reputation data" is increasingly becoming important in this sphere. Are you Facebook friends with people with a low credit score? Do you drive through a dodge neighborhood on the way to work? Do you watch the wrong kinds of movies? Buy liquor? Stream the wrong shows? It's all up for grabs, and with the "credit score" formulae locked up as trade secrets, there's no way to determine if your mortgage denial was because you were one day late with a cell phone bill, or because you stop at a red light next to a pawn shop enough times that your phone thinks you're a regular customer.
- 8y ago
- neffy 8y agoAnd in practice, we also don´t have completely free markets, and even if we did, it´s highly unlikely that they would function the way current economic theory believes that they would.
- pietroglyph 8y agoThe best part about the Equifax breach is that the people whose data was released weren't even the customers. Pretty hard to stop doing business if there wasn't any in the first place.
- r00fus 8y agoThe party in power is notorious for hypocrisy. Are no-bid contracts "free market"?
- MichaelApproved 8y agoIf Equifax breach didn't send anyone to jail, nothing will. A breach the size of Equifax should have followed with massive fines and possibly even killed the company but nothing happened.
- radium3d 8y agoThe concept of "I doubt you'd hear any competent IT director ever say they won't experience data breaches in the future." should tell you why we don't send people to jail for this type of thing. 100% prevention of breaches cannot be guaranteed ever [due to the infinite number of failure points in software and hardware as we've seen with the recent CPU hardware bugs, etc] so jailing IT people for breaches would only stop once every IT person was in jail because they didn't notice a line of code in millions of lines of code. There should be some level of competence of course, leaving things wide open doesn't seem safe, lol.
- emodendroket 8y agoThere is a bare minimum of precaution some of these cases don't seem to be followed.
- ghostbrainalpha 8y agoExactly. Yes these issue can be somewhat hard to understand for non security folks, but everyone can get the basics. 1. Do you have sensitive information? 2. Is a Password required to access that information? 3. Is that password set to "password" or something else that would be trivially easy to guess. It's like saying it's not your fault if a hacker takes extraordinary measures to tunnel into your house from below ground. But it is your responsibility to at least shut your front door.
- komali2 8y agoIt's about taking a reasonable level of security practice, like you said "some level of competency required." We require this of our bridges, and our roads, and our buildings. I'm not sure why we don't for our personal information assets. Arguably the Equifax hack will cause far greater economic loss than, say, a hole in the middle of mission street opening up due to lack of review by a civil engineer, so I don't get it. Is it because politicians are uneducated technically? We didn't have good fire law in America until a room full of seamstresses burned to death when the single exit was blocked off, do we need something similar for infosec? Equifax SHOULD have been that but whoever breached it didn't release yet (as far as I know) so maybe nobody is feeling the pain yet.
- nostromo 8y agoI actually don't think it needs to be criminal. We just need civil laws that make these kind of leaks incredibly costly. Maybe liability for private information loss could be $10k a user. So, Equifax would owe the public 1.4 trillion dollars. Of course, they wouldn't be able to pay that, so the company would be chopped up into bits and sold for scrap. I think that would catch more attention than some mid-level manager fall guy going to jail for six months, as would likely be the case with criminal proceedings.
- Tade0 8y agoMaybe liability for private information loss could be $10k a user. Or maybe up to 4% of the company's revenue.
- amonavis 8y agoUp to 4% of the company's revenue doesn't solve much. Depending on the sector, 4% of revenue (are we talking EBITDA?) may potentially be less than a slap on the wrist, and internally middle-management will take the blame for the reduction in sales margin/operating profit.
- reitanqild 8y agoParent said revenue, not EBITDA.
- lmkg 8y agoThe above comment is almost certainly a reference to GDPR, for which the maximum penalty for malicious non-compliance is "up to 4 % of the total worldwide annual turnover." It is not net income or profit or EBIDTA or anything else that subtracts operating cost, it is revenue.
- SmellyGeekBoy 8y agoStrange how anti-GDPR HN is... Until something like this happens.
- true_tuna 8y agoAt about this level
- chooseaname 8y agoNot soon enough.
- pwaai 8y agoAWS ceryfication should be mandatory in some industries.
- scarface74 8y agoI think you overestimate the abilities of “certified AWS Architects”. You can get one without ever logging into AWS. At least for the “Architect Associate”. You could probably get away without any practical experience for the Developer Associate. By the time I got that one though, I had practical experience. I did just that. I was a “software architect” for a company that was completely on prem that was moving to the cloud. Before I actually started working with AWS, I actually wanted to do it correctly and wanted an overview of the services offered. For $reasons, I left that company about a year ago before ever touching the AWS console, and based partially on my “certificate”, I got another job and was given admin access to AWS. I spent the next year actually getting practical experience.