Credit reporting firm Equifax says data breach could potentially affect 143 million US consumers

Discussion in 'other security issues & news' started by ronjor, Sep 7, 2017.

  1. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  2. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  3. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "...Dispute between Equifax and Mandiant widened attackers' window of opportunity...

    'The hackers were finally discovered on July 29, but were so deeply embedded that the company was forced to take a consumer complaint portal offline for 11 days while the security team found and closed the backdoors the intruders had set up,' according to Bloomberg, which claims to have reconstructed the attack via interviews with people involved in the investigations being conducted by both Equifax and the FBI.

    It suggests that the attack coincided with a dispute between Equifax and Mandiant, one of its security partners brought-in to help deal with a different security problem, just as the attack was getting underway. Equifax accused Mandiant of using the classic consulting sales trick of using the A-team to sell its services and sending in the B-team after the contract was signed.

    This dispute led Equifax to ignore the initial results of Mandiant's work indicated "unpatched systems and misconfigured security policies" - although these claims might equally indicate backside covering on the part of Mandiant..."

    https://www.computing.co.uk/ctg/new...rsonnel-management-hack-of-2015-claim-reports
     
  4. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,648
    Location:
    U.S.A.
    Equifax Warned About Vulnerability, Didn't Patch It: Ex-CEO
    http://www.securityweek.com/equifax-warned-about-vulnerability-didnt-patch-it-ex-ceo
     
  5. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,692
    Location:
    Paris
    As current Mandiant Geeks would never lower themselves to respond to the Equifax libel, allow me to do so.

    A Mandiant team consists of a bunch of Folk: there are Rookies to do the grunt work and observe how their Betters operate, there are experienced Blackhats turned White to do the analysis, and there is a Team leader to Rule Them All. Never Ever (never ever) is there whole Team composed of "B-listers". Never Ever. Normally modesty would stop me from admitting that the M team leader will be the smartest Security person that ever condescended to speak to the Board, but sometimes you have to call a Spade a Spade.

    Sadly those in power in the company realize that the cost of remediation often will exceed any subsequent penalty (and the CEO will always throw himself on a Golden sword); also there is the knowledge that (if the company is publicly traded) the Stock price will rebound shortly after the general public forgets about the breach, thus providing another opportunity for insiders to profit mightily from the despair of the Great Unwashed.

    My advice- set up a brokerage account with the ability to buy Options. Next time you see a major breach of a Company wait a week, mortgage everything you own and buy long term options on the stock. You will have a vacation house on the beach in Barbados in short order.
     
  6. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
  7. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    From the currently ongoing Congressional Hearing on Equifax

    The former music major CSO has "been unavailable" to supply information -- hmmmm

    https://www.c-span.org/video/?434786-1/former-equifax-ceo-testifies-data-breach&live

    Maybe she's been in Paraguay or something.

    Shows a lack of aggressiveness by The Sub Committee Chairman-- if he really wanted to speak with her or compel her to testify a suboena could have been issued.
     
    Last edited: Oct 3, 2017
  8. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  9. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    Last edited: Oct 3, 2017
  10. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
  11. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  12. Acadia

    Acadia Registered Member

    Joined:
    Sep 8, 2002
    Posts:
    4,366
    Location:
    US
  13. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,652
    Location:
    Triassic
    Those in the IRS who proposed this contract be sole sourced to Equifax and those who approved it should be taken to task by the Secretary of the Treasury. This decision shows a lack of due diligence and absolute ineptitude at the IRS. The IRS commissioner needs to step in , step up or step aside. His silence is deafening. The cozy relationship that Equifax has had with the IRS should be severed. The Lawmakers and The Treasury already have 145.5 million reasons to act post haste.

    Lawmakers should also be blasted for allowing SSNs as a proof of identity outside of the SSA distribution of government services. SSNs are no longer a trusted ID due to the breach at Equifax. Consumers (that word for citizens today) are in desperate need of a solution. There is no solution being proposed for this right now and it gives the impression that the government does not know what to do or how to go about it. Where is the urgency? This will prove to be a major security faux pas on their part.
     
  14. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
  15. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    106,615
    Location:
    U.S.A.
  16. plat1098

    plat1098 Guest

    Well, the word "horror" just sucks you right in, lol. Of the 6 listed, though, I found #5 (a state-sponsored act) to be the most "horrifying." The other five to me appeared to be teetering if not toppling over into criminality and shouldn't go un-punished/prosecuted. Come on! Let's start breaking some of those barriers money and power automatically buy. Enough already. Our personal info has already been stolen, bartered and sold as it is.
     
  17. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    And Now!! For our next trick to Amaze and Enthrall you!!
    The Great, New World Orderonzo will get the entire US Adult population to accept!!
    Wait for it!!
    Drum roll ..
    Yes!! You guessed it!!!
    He will make happen before you very eyes, the entire US Adult population accept and embrace,
    !!!Biometric ID Authentication!!!
    Without barely as a wimper from the civil rights organisations!!
     
  18. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    Last edited: Oct 5, 2017
  19. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,907
    Location:
    Slovenia, EU
    https://www.cnet.com/news/equifax-trump-white-house-official-replace-social-security-numbers/
     
  20. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,652
    Location:
    Triassic
    @Minimalist. Nice find.

    My new hero - NSA's onetime top hacker, Rob Joyce.
     
  21. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    Hmmm well perhaps I was wrong on this one. I was looking at the Equifax breach as the identity theft "Pearl Harbour", or "9/11" that would be used to push the biometrics or facial recognition technology that a great many people currently feel uncomfortable with, into mainstream use.
    Rob Joyce is talking about a far more acceptable solution so I hope his ideas get the government backing they will need.
     
    Last edited: Oct 5, 2017
  22. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  23. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  24. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  25. compleo

    compleo Registered Member

    Joined:
    May 3, 2016
    Posts:
    134
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice