snowride509 

37 Followers
117 Following
43 Posts
Dad and Husband. InfoSec & technology nerd. Dog lover. Ally to all. CISSP.
@zackwhittaker @hak1mlukha
https://www.cisa.gov/coordinated-vulnerability-disclosure-process
Going straight to the media rather than following CVD is not "good faith" research.
@hak1mlukha
"Anurag Sen, a good-faith security researcher...found the exposed server over the weekend and provided details to TechCrunch so we could alert the U.S. government."
Why go straight to the media instead of alerting the vendor first? That kind of behavior is more black hat than "good faith"

Notified Experian on Dec. 23 that their site was allowing anyone to see the credit report for, well, basically anyone, completely bypassing their lame 4-5 multiple guess questions and other security.

Or even in cases (like mine) where trying to get your credit report generates an error saying you have 3 other options for getting your free report from them (calling, mailing, or chat w/ rep). The site said Experian didn't have enough info to validate my identity, but when I changed the url slightly, it showed me my entire report. Glad I checked, too, because the info in there is so completely wrong I don't even know where to start.

So it's Dec. 27, and I still haven't heard anything from Experian. All you needed was the person's name, address, SSN and DOB. This info has been exposed on pretty much most Americans for many years now.

BTW, I checked this with several friends who volunteered to check their own reports, and they were able to fully replicate what I did.

It's bad enough that we can't stop companies like Experian from making $2B a quarter collecting and selling our info, but there has to be some real accountability. And as we saw with the Equifax settlement, class-actions and more laughable "credit monitoring" services aren't going to cut it.

Experian has shown this year especially that it gives exactly zero fscks about securing access to the data that drives its entire business.

https://krebsonsecurity.com/2022/08/class-action-targets-experian-over-account-security/

https://krebsonsecurity.com/2022/07/experian-you-have-some-explaining-to-do/

https://krebsonsecurity.com/2021/04/experian-api-exposed-credit-scores-of-most-americans/

Class Action Targets Experian Over Account Security – Krebs on Security

He talked about electric cars. I don't know anything about cars, so when people said he was a genius I figured he must be a genius.

Then he talked about rockets. I don't know anything about rockets, so when people said he was a genius I figured he must be a genius.

Now he talks about software. I happen to know a lot about software & Elon Musk is saying the stupidest shit I've ever heard anyone say, so when people say he's a genius I figure I should stay the hell away from his cars and rockets.

I keep seeing that “first they came for the journalists” sign, and it pisses me off so much, because when they came for muslims, immigrants, and trans people, mainstream journalists normalized it and reported it as “both sides”. Somehow it didn’t count for them until it was happening to them personally, which is *exactly* what the fucking poem was warning against in the first place.

Can we also take a moment to note that "woke", as used here, was originally a Black American term for being aware of systemic racism, and in just a few years, the US right turned it into a totally content-free sneer? And the entire English-speaking media basically just ran with it, to the extent that you now hear it used in _Finnish_?

Because that's white supremacy for you. Criticism, even awareness, of the racist power structure will not be tolerated.

@ajohnsocyber welcome to the party!
Infosec.exchange crossed 40000 accounts a few minutes ago. 7 weeks ago, we had ~180 active accounts.