Welcome!

Machine Learning Authors: Elizabeth White, Yeshim Deniz, Pat Romanski, Liz McMillan, Ed Featherston

Related Topics: @CloudExpo, Cloud Security, @BigDataExpo

@CloudExpo: Article

Equifax Is an Enron Moment | @CloudExpo #AI #DX #SDN #Cybersecurity

What makes this specific breach even more damaging is the type of the stolen data

Equifax Is an Enron Moment, But Not the Way You May Think

Enron changed how U.S. public companies audit and report their financial data. There is also an opportunity to use the Equifax data breach to create a framework for better protection of our data in future.

The credit reporting agency reported one of the largest data breaches in the history. Hackers were able to steal sensitive information from its internal servers. The stolen data include name, Social Security Number (SSN), date of birth, and also credit card numbers and driver license numbers in some cases. A massive breach like this can haunt the victims for years to come.

What makes this specific breach even more damaging is the type of the stolen data. If someone steals your credit card number, you call your bank and get a new card hopefully before the hacker is able to make use of the stolen card. But, if a hacker gets your date of birth, good luck trying to change it. In fact, thieves are known to sit idle for months waiting for increased awareness after the breach to subside before hitting the underground market with stolen SSN and dates of birth. If you are one of the 143 million people affected by this breach, get used to the feeling of being haunted. Hackers may use stolen data tomorrow or in multiple years from now. They have all the data needed to reset bank passwords, access health records, open credit card accounts on your behalf, etc. You will never know when or how they will misuse your data.

Equifax has been less than forthcoming in describing how the hackers were able to get to the most sensitive data. Baird Equity Research attributes the breach to a flaw in Apache Struts, one of the most popular software for developing Java-based web applications. A new vulnerability was reported recently in Apache Struts that allows hackers to remotely run arbitrary commands on the server. It's conceivable and even probable that either this vulnerability or another one like it was used for this hack. What's troubling is these vulnerabilities have existed for long time but were identified and mitigated only recently. Such vulnerabilities provide hackers enough time to target organizations with prized data and steal the data for nefarious use.

Albert Einstein is credited with the saying that the definition of insanity is doing the same thing over and over again, but expecting different results. If we, as a society, are to get better at protecting our most critical data, we have to try something new. Obviously, the law enforcement agencies will be spending a good amount of time reviewing Equifax's security processes, response, and the unfortunate timing of their executives trading stocks. However, this data breach is just one of the many, and while it looks pretty jarring, there is this uncanny feeling there is worse to come.

Some have argued for not using SSN as a means of identification. SSN was designed to track income and not a way to identify or authenticate people. However, such a move misses the big picture. SSN is one of the sensitive pieces of information we have, but as past breaches have taught us there are plenty more - date of birth, passwords, health record, employment history, etc. How are doing to protect them? We need a method to protect all sensitive data. Fortunately, technology can now offer such a required solution and with a little bit of public help, we can make meaningful progress in stopping the incessant data thefts.

One approach to preventing some of these mega breaches, including Equifax, is an innovative use of encryption. Encryption already secures data at rest. For example, if you use self-encrypting hard drives, or Microsoft Bitlocker, you are securing your data using encryption when it's sitting idle. Similarly, encryption secures your data in transit. When you connect to your bank website using your browser or mobile phone application, Transport Layer Security (TLS) protects data as it moves from you to the bank servers. When the banks provide the data to Equifax, they also use TLS. However, once the data is used by Equifax, it's decrypted and exposed. The exposed data works like a magnet for hackers and they try all possible vulnerabilities to find and steal the exposed data. In the case of Equifax, Apache Struts provided the path for the hackers to connect to the exposed data.

Encryption during runtime keeps data encrypted when applications are using the data. This allows organizations to limit access to data to the actual business logic running on the server. Had Equifax encrypted data during runtime, even with vulnerable Apache Struts hackers would have accessed only encrypted data which they wouldn't be able to decipher. Encryption during runtime understands that hackers will always be able to use vulnerable applications to connect to the servers. The best strategy is to ensure that even when this happens, the data we care about remains encrypted and therefore undecipherable to hackers.

Encryption during runtime is certainly not a panacea and cannot protect from all threats. For example, if the business logic itself is vulnerable, the data could still be compromised. However, it protects the data from all vulnerabilities that are found in code other than the business logic. An approach that combines encryption with best practices in developing secure applications can reach new limits in securing data.

When the Enron scandal was reported in 2001, the Congress legislated the Sarbanes-Oxley Act that increased audit requirements and made it harder for companies to fudge their financial numbers. It has been effective in avoiding another Enron-like scandal. If you don't want to see a repeat of the Equifax data breach, a good place to start may be with your congressman. Ask him or her to strengthen data breach laws and to require organizations to disclose how they protect your data in use. Disclosure of the internal security practices along with regulatory requirements can create a virtuous cycle where the most secure organizations are rewarded with more business. No bank would dare to operate their website without TLS today. Otherwise regulators, customers, security analysts, social media, etc., all will publicly punish and shame them. We need encryption during runtime for processing sensitive data.

More Stories By Ambuj Kumar

Ambuj Kumar is CEO and Co-founder of Fortanix. Prior to founding Fortanix, he was lead architect at Cryptography Research Inc. where he led and developed many of the company's security technologies that go into millions of devices every year. Previously, he worked for NVIDIA where he designed the world's most advanced computer chips including the world's fastest memory controller. He has a Bachelor of Technology from IIT Kanpur and an MS from Stanford University, both in EE.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
SYS-CON Events announced today that Evatronix will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Evatronix SA offers comprehensive solutions in the design and implementation of electronic systems, in CAD / CAM deployment, and also is a designer and manufacturer of advanced 3D scanners for professional applications.
As businesses evolve, they need technology that is simple to help them succeed today and flexible enough to help them build for tomorrow. Chrome is fit for the workplace of the future — providing a secure, consistent user experience across a range of devices that can be used anywhere. In her session at 21st Cloud Expo, Vidya Nagarajan, a Senior Product Manager at Google, will take a look at various options as to how ChromeOS can be leveraged to interact with people on the devices, and formats th...
First generation hyperconverged solutions have taken the data center by storm, rapidly proliferating in pockets everywhere to provide further consolidation of floor space and workloads. These first generation solutions are not without challenges, however. In his session at 21st Cloud Expo, Wes Talbert, a Principal Architect and results-driven enterprise sales leader at NetApp, will discuss how the HCI solution of tomorrow will integrate with the public cloud to deliver a quality hybrid cloud e...
Is advanced scheduling in Kubernetes achievable? Yes, however, how do you properly accommodate every real-life scenario that a Kubernetes user might encounter? How do you leverage advanced scheduling techniques to shape and describe each scenario in easy-to-use rules and configurations? In his session at @DevOpsSummit at 21st Cloud Expo, Oleg Chunikhin, CTO at Kublr, will answer these questions and demonstrate techniques for implementing advanced scheduling. For example, using spot instances ...
SYS-CON Events announced today that Taica will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Taica manufacturers Alpha-GEL brand silicone components and materials, which maintain outstanding performance over a wide temperature range -40C to +200C. For more information, visit http://www.taica.co.jp/english/.
When it comes to cloud computing, the ability to turn massive amounts of compute cores on and off on demand sounds attractive to IT staff, who need to manage peaks and valleys in user activity. With cloud bursting, the majority of the data can stay on premises while tapping into compute from public cloud providers, reducing risk and minimizing need to move large files. In his session at 18th Cloud Expo, Scott Jeschonek, Director of Product Management at Avere Systems, discussed the IT and busine...
Organizations do not need a Big Data strategy; they need a business strategy that incorporates Big Data. Most organizations lack a road map for using Big Data to optimize key business processes, deliver a differentiated customer experience, or uncover new business opportunities. They do not understand what’s possible with respect to integrating Big Data into the business model.
Enterprises have taken advantage of IoT to achieve important revenue and cost advantages. What is less apparent is how incumbent enterprises operating at scale have, following success with IoT, built analytic, operations management and software development capabilities – ranging from autonomous vehicles to manageable robotics installations. They have embraced these capabilities as if they were Silicon Valley startups. As a result, many firms employ new business models that place enormous impor...
Amazon is pursuing new markets and disrupting industries at an incredible pace. Almost every industry seems to be in its crosshairs. Companies and industries that once thought they were safe are now worried about being “Amazoned.”. The new watch word should be “Be afraid. Be very afraid.” In his session 21st Cloud Expo, Chris Kocher, a co-founder of Grey Heron, will address questions such as: What new areas is Amazon disrupting? How are they doing this? Where are they likely to go? What are th...
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
SYS-CON Events announced today that Dasher Technologies will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Dasher Technologies, Inc. ® is a premier IT solution provider that delivers expert technical resources along with trusted account executives to architect and deliver complete IT solutions and services to help our clients execute their goals, plans and objectives. Since 1999, we'v...
Though cloud is the future of enterprise computing, a smooth transition of legacy applications and systems is critical for seamless business operations. IT professionals are eager to start leveraging the cost, scale and other benefits of cloud, but with massive investments already in place in existing infrastructure and a number of compliance and resource hurdles, it can be challenging to move to a cloud-based infrastructure.
SYS-CON Events announced today that NetApp has been named “Bronze Sponsor” of SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. NetApp is the data authority for hybrid cloud. NetApp provides a full range of hybrid cloud data services that simplify management of applications and data across cloud and on-premises environments to accelerate digital transformation. Together with their partners, NetApp emp...
In his session at 21st Cloud Expo, Raju Shreewastava, founder of Big Data Trunk, will provide a fun and simple way to introduce Machine Leaning to anyone and everyone. Together we will solve a machine learning problem and find an easy way to be able to do machine learning without even coding. Raju Shreewastava is the founder of Big Data Trunk (www.BigDataTrunk.com), a Big Data Training and consulting firm with offices in the United States. He previously led the data warehouse/business intellige...
SYS-CON Events announced today that IBM has been named “Diamond Sponsor” of SYS-CON's 21st Cloud Expo, which will take place on October 31 through November 2nd 2017 at the Santa Clara Convention Center in Santa Clara, California.
SYS-CON Events announced today that TidalScale, a leading provider of systems and services, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale has been involved in shaping the computing landscape. They've designed, developed and deployed some of the most important and successful systems and services in the history of the computing industry - internet, Ethernet, operating s...
Infoblox delivers Actionable Network Intelligence to enterprise, government, and service provider customers around the world. They are the industry leader in DNS, DHCP, and IP address management, the category known as DDI. We empower thousands of organizations to control and secure their networks from the core-enabling them to increase efficiency and visibility, improve customer service, and meet compliance requirements.
In his session at 21st Cloud Expo, Michael Burley, a Senior Business Development Executive in IT Services at NetApp, will describe how NetApp designed a three-year program of work to migrate 25PB of a major telco's enterprise data to a new STaaS platform, and then secured a long-term contract to manage and operate the platform. This significant program blended the best of NetApp’s solutions and services capabilities to enable this telco’s successful adoption of private cloud storage and launchi...
Data scientists must access high-performance computing resources across a wide-area network. To achieve cloud-based HPC visualization, researchers must transfer datasets and visualization results efficiently. HPC clusters now compute GPU-accelerated visualization in the cloud cluster. To efficiently display results remotely, a high-performance, low-latency protocol transfers the display from the cluster to a remote desktop. Further, tools to easily mount remote datasets and efficiently transfer...
SYS-CON Events announced today that IBM has been named “Diamond Sponsor” of SYS-CON's 21st Cloud Expo, which will take place on October 31 through November 2nd 2017 at the Santa Clara Convention Center in Santa Clara, California.