Skip to content

Entirely Preventable

The patch existed for two months. The scanner missed the vulnerable system. The monitoring was blind behind a certificate that had expired nineteen months earlier. And the financial identities of 147 million people walked out of Equifax. The congressional verdict is this article's title.

Episode 204 minute read

The breach that defined a decade

In September 2017, Equifax, one of the three US credit bureaus, holding financial identity data on most American adults by the nature of its business, disclosed a breach in which the personal data of about 147 million people was taken: names, Social Security numbers, birth dates, addresses, and for subsets, driver's license and card numbers. The population affected had, overwhelmingly, never chosen to be Equifax customers; a credit bureau's subjects are conscripted by the financial system itself, which is why the breach became the reference case for data stewardship obligations and why the House Oversight Committee's investigation, whose record this article follows, concluded in the two words that serve as this article's title: the breach was entirely preventable.

This series places Equifax at the head of its security arc to establish the arc's thesis: the incidents ahead are security failures on the surface and verification failures underneath, and Equifax is the thesis in its purest documented form, because every gate that failed was a testing gate. The timeline, per the congressional record: in early March 2017, a vulnerability in Apache Struts, a web framework Equifax used, was publicly disclosed with a patch available; Equifax received the alert and circulated it internally, instructing that affected systems be patched. The vulnerable system, a consumer dispute portal, was not identified, so it was not patched: the instruction was issued and its execution was never verified against a complete inventory. A vulnerability scan run days later failed to find the vulnerable system: the scan's coverage was itself unvalidated, a test that could not fail because it could not see. Attackers entered in mid May and operated until late July, about 76 days, and the duration had its own cause: a device intended to inspect encrypted traffic had an expired certificate, expired roughly nineteen months earlier, leaving the monitoring effectively blind; when the certificate was finally renewed, suspicious traffic was spotted almost immediately, which is the record's own proof of what working monitoring would have seen in May. The consequences ran to the departure of the CEO and senior executives and a settlement with US authorities of up to around 700 million dollars.

What it teaches

First, an unverified control is a hope with a budget line: the patch instruction existed, the scanner existed, the monitoring device existed, and each one's actual function was assumed rather than demonstrated, so the organization's security posture was, in this series' standing term for a control nobody has exercised, a set of untested hypotheses; the discipline the congressional findings translate into is closed loop verification, every patch instruction confirmed against inventory, every scanner validated against known vulnerable targets, every monitoring path proven with test traffic, because a control that has never been shown to work is indistinguishable, on the day it matters, from one that does not. Second, asset inventory is the foundation every other control stands on: the system was missed because it was not known in the way the process needed it known, and the unglamorous work of complete, current inventory, which this series has watched decide outcomes from GPS rollovers to the 2038 problem, here decided the financial privacy of a nation; you cannot patch, scan, or monitor what you cannot enumerate. Third, certificate lifecycle is a security function, not an administrative one: nineteen months of expired blindness on the inspection path converted a breach into a 76 day occupation, and the O2/Ericsson article in this series' telecom arc already taught the mechanical lesson, that certificates are timers wired to capabilities; Equifax adds the security corollary, that the expiry of a monitoring certificate should page someone with the same urgency as the intrusion it would otherwise miss. The attackers exploited a known flaw with a public fix. Everything else, the inventory gap, the blind scan, the dead certificate, was process, and the committee's verdict stands as this arc's epigraph: entirely preventable is a technical finding, and it is the finding this entire series exists to make boring through repetition.

Sources

5 sources

Every figure in this article traces to one of the following: the same record the episode cites.

  1. The Equifax Data Breach

    Majority Staff Report, U.S. House of Representatives Committee on Oversight and Government Reform, December 20182018

  2. Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach

    United States Government Accountability Office (GAO-18-559)2018

  3. Form 10-K for the fiscal year ended December 31, 2018

    Equifax Inc., filed with the U.S. Securities and Exchange Commission (EDGAR)2019

01Zof Console

سطح واحد للوضعية والعمليات وما يحتاج إلى الاهتمام بعد ذلك.

المنزل المُوثَّق الذي تفتحه فرق الهندسة وضمان الجودة وSRE كل يوم: وضعية الجودة، والتشغيل الجاري، والتغطية حسب الوحدة، وما يحتاج إلى الانتباه تاليًا.

مؤشرات الأداء الرئيسية التشغيلية

  • أشواط
  • تغطية
  • خطر

عش عبر كل بيئة تشحن إليها.

العمود الفقري للعمل

  • المواصفات
  • الاختبارات
  • الجداول

من المواصفات إلى الانحدار المجدول.

الدرابزين

  • RBAC
  • SSO
  • التدقيق

كل فعل ينسب إلى إنسان مسمى.

LIVE/console
يعرض مركز القيادة المنزلي Zof AI 12 عملية تشغيل بنسبة نجاح 94%، و3 مشكلات حرجة مفتوحة، وتغطية 84%، وأربعة أشرطة لتتبع الوحدات النمطية، ومسار المواصفات، والجداول الزمنية القادمة، والإجراءات التالية الموصى بها مع شريط جانبي للتشغيل النشط.
عرض الصفحة الرئيسية · خدمة الخروج · التدريج · تم التقاطها مباشرة من المنتج.
Entirely Preventable | Zof AI