1
0

Fall guy-Former Equifax CEO blames breach on one iT guy.


 invite response                
2017 Oct 4, 6:30am   1,409 views  2 comments

by lostand confused   ➕follow (3)   💰tip   ignore  

https://finance.yahoo.com/news/former-equifax-ceo-blames-breach-202000503.html

The Equifax data breach that leaked information on the now-145 million people was caused by a vulnerability in Apache's Struts system. Trouble is, the software provider supplied a patch back in March that should have eliminated that vulnerability. But Equifax's former CEO (who suddenly retired last week) told the House Energy and Commerce Committee that a single IT technician was at fault for the whole thing after they failed to install the patch.

Comments 1 - 2 of 2        Search these comments

1   zzyzzx   2017 Oct 4, 6:50am  

Probably a H1B.
2   Tenpoundbass   2017 Oct 4, 7:02am  

Why would a huge company like that not have their own Super computer? Why would they be using Apache and open source for something so important?

Also why wasn't the data not canonicalized and obfuscated? I bet the database table names has table names like "Creditor" "Debtor" with fields like "FirstName" and "SocialSecurityNumber" The data should have been stored in an unsuable state, and the only way it makes any sense, is by running through proprietary EF algorithms upon retrieval, one Credit report at a time. No bulk dump data. There's no reason for them to even partake in List Name exchanges. That should be made illegal straight away.

Please register to comment:

api   best comments   contact   latest images   memes   one year ago   random   suggestions