Wednesday, December 12, 2018

Equifax breach was entirely preventable according to House Oversight and Government Reform Committee 96 Page Report

The House Oversight and Government Reform Committee, following a 14-month probe, released a scathing report Monday saying the consumer credit reporting agency aggressively collected data on millions of consumers and businesses while failing to take key steps to secure such information. "In 2005, former Equifax Chief Executive Officer (CEO) Richard Smith embarked on an aggressive growth strategy, leading to the acquisition of multiple companies, information technology (IT) systems, and data," according to the 96-page report authored by Republicans. "Equifax, however, failed to implement an adequate security program to protect this sensitive data. As a result, Equifax allowed one of the largest data breaches in U.S. history. Such a breach was entirely preventable."

The cause of the leak revealed - new facts


It was previously disclosed an unpatched version of Apache struts was to blame. But new in this report, Chinese attackers began a cyberattack on Equifax. The attack lasted for 76 days. The attackers dropped “web shells” (a web-based backdoor) to obtain remote control over Equifax’s network.

Attackers sent 9,000 queries on these 48 databases, successfully locating unencrypted personally identifiable information (PII) data 265 times. The attackers transferred this data out of the Equifax environment, unbeknownst to Equifax. Equifax did not see the data exfiltration because the device used to monitor ACIS network traffic had been inactive for 19 months due to an expired security certificate. On July 29, 2017, Equifax updated the expired certificate and immediately noticed suspicious web traffic.

Outcome in my humble opinion

Expect to see your private information for sale on the darknet and extortion schemes soon. 

Why is Equifax still allowed to operate?

Microsoft has confirmed that the upcoming Chromium-based Edge browser will also be able to run Chrome extensions




Microsoft has confirmed that the upcoming Chromium-based Edge browser will also be able to run Chrome extensions.



Sounds great but Chrome extensions are common hacking methods for performing malicious activity such as; 
  • hijacking your search pages
  • injecting ads
  • stealing contact information from logged in accounts
  • registering free domains for attackers
  • stealing account credentials
  • and injecting in-browser crypto-currency miners.

Friday, December 7, 2018

Microsoft Edge's switch to Google's Chromium is bad news for privacy

Well it's official Microsoft announced that it seems it will swap out EdgeHTML for Chromium's Blink engine. 

One of the primary reasons is that "Microsoft Edge will now be delivered and updated for all supported versions of Windows and on a more frequent cadence.

This supports Microsoft Agile objectives but clearly this methodology has not done so well with Microsoft Updates. Microsoft had to pull October 2018 update after many issues plagued it. It's not about speed, it's about quality.

Seems Mozilla is not too happy either, as it erodes the competition and give another advantage to Google-plex. Also, developers might want to just develop to Chrome browser and stop support IE and Edge altogether now. And the the cards will fall, and Microsoft will stop supporting IE and Edge for internal corporate website, where IE still has authentication advantages and uses.



Another huge issue is privacy, Chromium built-in tracking features unavoidable leak private information to Google-plex. Not sure how Microsoft will shore up their privacy policy or prevent this entirely. 

Let's hope Microsoft does the right thing and prevent communication to Google servers entirely.