|
|
Log in / Subscribe / Register

Apache Struts Statement on Equifax Security Breach

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 15:12 UTC (Mon) by drag (guest, #31333)
In reply to: Apache Struts Statement on Equifax Security Breach by ledow
Parent article: Apache Struts Statement on Equifax Security Breach

It is very likely not a single vulnerability that caused the breach.

Modern datacenters are extraordinarily complex systems. They are always going to be vulnerabilities. There are always going to be bad procedures, logs that are missed, applications that are wrong, systems that are in bad health, operators that are asleep or distracted, hard drives failing, etc etc. That's the nature of any complex system.

Once it rises above a certain amount of size and complexity then failures are the norm, not the exception.

In the case of credit cards information... if it's stored and made available to user accounts on the front-end and for billpay or whatever you need that information for.. then it doesn't matter how far and how deep you bury the storage. You could have a hundred networks, a thousand servers, a million firewalls and yet there is going to be a path from external systems to that credit card information. Without such a path it couldn't possibly work.

The only way to come close to 100% secure that sort of information is to never store that information in the first place and even then it's possible to leak numbers out into the wild.

So what happenned here, more then likely (I haven't looked at this particular case closely) is a cascade of failures. If the apache strut problem never existed then maybe the criminals would of just found a different way to exploit all the other failures that existed.


to post comments

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 18:07 UTC (Mon) by Nelson (subscriber, #21712) [Link] (6 responses)

100% secure is very difficult.

A 100% complete and totally catastrophic failure is kind of difficult too though. You have to be pretty bad at things to have a complete failure like this. Being that their core business is selling queries to their databases, you'd think that just to bill correctly they'd have systems in place that would make it obvious when an unusual amount of traffic was being generated or something like that. There are lots of other questions too, they accept credit cards for payment to their various services, they should supposedly be PCI compliant and have undergone some routine audits; those and the exceptions they may have applied for would be very interesting details. I'd expect all these things to be completely separate concerns in a well architected business and this type of failure would require an APT that exploited numerous internal systems over a long period of time, pinning it on struts would be sort of a joke with that kind of situation.

Funny story about equifax. I have paid for their credit monitoring and fraud protection service for about 12 years (just canceled it over the weekend..) FWIW, the family plan pricing was pretty affordable compared to a lot of the alternatives. About 5 years ago it saved my bacon, a car dealership (I'm very certain of it) leaked my information and in a 3 day period 4 new credit accounts were opened in my name and there were 7-10 credit checks run on me. EFX notified me and I was able to shut it down quickly. It's ironic, I was thinking of ending the service but that happened. It cost me nothing but some stress as it was a Sunday and I had to make a dozen or so phone calls; so some stress and 2 hours on the phone. The next month, I got another alert from them, my credit rating dropped, I want to say about 13 points in Equifax' score but it was still in the great category, it was an inconsequential drop but it sounded and felt big and I watch the stuff like a hawk. I remember working very hard to get above 800 and it took a long time for those last few points. I called EFX up to inquire, I hadn't done anything but shut down some frauds that I reported to them, I was worried something else was going on. They told me that there were too many credit checks done on me and that can lower your credit score, I insisted that that didn't happen but they pointed to the 7-10 credit checks that were done fraudulently and I had reported to them. I won't bore you with the details but they wouldn't fix their own score even though I reported the fraud, they told me the score will naturally recover in time, that's the best they could do. That's the kind of business they are. Again, that goes back to my point about them being able to actually audit the queries to their database and bill correctly for them, cause it potentially hurts consumers with their own algorithms; likewise if they give their entire database to partners for some business reasons, then there are potentially queries that aren't factored in and maybe they should be.

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 19:50 UTC (Mon) by drag (guest, #31333) [Link] (5 responses)

> You have to be pretty bad at things to have a complete failure like this.

Everybody is this bad at this.

Organizations, unless checked by some external force, will have a tendency to grow continuously in complexity and size up until the point where the bureaucracy is reaches a sort of plateau of critical maximum inefficiency. The critical maximum inefficiency is where people have spent so much time dealing with the bureaucracy that they really don't have any time to do anything else... including making the bureaucracy more complicated. PCI compliance and audits and such things are just a example of bureaucratic road blocks to help manage risk. This is natural, often desirable, and are unavoidable in large organizations. But they are not silver bullets.

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 20:10 UTC (Mon) by jebba (guest, #4439) [Link] (2 responses)

Everyone isn't this bad at this.

To find out if you were compromised by Equifax, a PR company set up a Wordpress website with shared SSL certificates, and javascript pulled from multiple outside servers. This is just asking for it.

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 20:38 UTC (Mon) by ssmith32 (subscriber, #72404) [Link] (1 responses)

Even better, a reporter tried putting in random names and numbers to the WordPress site, and the response was the same, regardless..

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 21:05 UTC (Mon) by jebba (guest, #4439) [Link]

And the security PIN they assign at the end of the process is the timestamp, like 0911170330 for 3:30AM on 9/11...

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 21:48 UTC (Mon) by Nelson (subscriber, #21712) [Link] (1 responses)

Not everybody is bad at this stuff, that's just not true. Who else is this bad at it? HBO and Sony are the only examples that come to my mind and they didn't lose my private data. There is another analogue: how many times has Amazon or Walmart shipped something that they sell that wasn't actually bought on their website? Don't forget that they sell access to this data, that's how they make money. There very business model requires auditing access to it, they need to have those kinds of systems in place just to do what they say they do.

I'm not suggesting that PCI compliance is a silver bullet here, I'm simply asking if they were compliant or what exceptions they had. They would have had to undergo a third party audit, Verizon or somebody gave them a stamp of approval.. I think this sort of event might be the external force that checks these guys. Get those names out there, get the details out there.

Apache Struts Statement on Equifax Security Breach

Posted Sep 12, 2017 3:06 UTC (Tue) by drag (guest, #31333) [Link]

Every single company you mentioned had significant data breaches at one point or another.

> I'm simply asking if they were compliant or what exceptions they had.

From my experience working in the financial system.. If there is a regulation or industry standard this company would comply with it. That's just par for the course. Not even a question. They are a core part of how the financial industry in the USA functions on a fundamental level.

When you get to this level the difference between who does the regulation and who is the regulated starts to get very blurry. I don't know the details ,but I entirely expect that Equifax is going to have very close relationship with the major banks in the USA, which are the ones that are responsible for defining and enforcing PCI standards since they are the people that own the credit card companies.

Apache Struts Statement on Equifax Security Breach

Posted Sep 11, 2017 20:43 UTC (Mon) by ssmith32 (subscriber, #72404) [Link]

There's no need for one service to have access to ALL the data:
1) each service should only manage a slice of the data; ssn, DL, address, etc. All information is merged on the front end, not in a single service.
2) per connection/per user/per session quotas. It should not be possible to request more than X records, even in the slice of the data that the service manages.

So, yes, it looks like there may have been some really dumb mistakes made.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds