TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

First American Financial Corp. Leaked Hundreds of Millions of Insurance Records

418 pointsby PatrolXalmost 6 years ago

18 comments

client4almost 6 years ago
I did a penetration test for $NATIONALINSURER and they had an FTP site with weak credentials where all the remote offices uploaded claims. Millions of records and scans of SSNs, home addresses, bank information, etc. Their mitigating controls were: we put it behind a firewall.<p>Then again I didn&#x27;t expect much, their MSSQL in prod had SA&#x2F;SA credentials active.
评论 #20005632 未加载
评论 #20006223 未加载
评论 #20005616 未加载
评论 #20005719 未加载
zhte415almost 6 years ago
A lot of discussion on technical side, but not from organisational.<p>How could audit, both internal and external, not find this? 2003 to today is 16 years. Audit is a last line of defence and certainly not to be relied on upon as a buddy to catch your errors. But... how? This is a major financial institution in the most developed country in the world (the clue&#x27;s in the name). It should subscribe to the the highest integrity and tightest scrutiny. This seems an opportunity for both internal and external auditors to tighten their game.<p>Outside of audit, surely an employee might have noticed? Was there no formal method to speak up without fear of recrimination? According to Wikipedia [1] there are eighteen thousand employees. Someone never noticed?<p>This seems an organsiational failing, not a technical one.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;First_American_Corporation" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;First_American_Corporation</a>
评论 #20007449 未加载
评论 #20007345 未加载
评论 #20008356 未加载
评论 #20007213 未加载
angry_octetalmost 6 years ago
Whenever you are compelled to upload&#x2F;send a photocopy of an ID document it is sensible to write the date and purpose &#x2F; file reference on it. If it appears in a document dump at some later date you know the path and date of the leak.
评论 #20007133 未加载
评论 #20006570 未加载
throwawaymathalmost 6 years ago
Yet another security vulnerability caused by:<p>1. Using sequentially incremented integer sequences as object IDs, and<p>2. Failing to protect sensitive data using some kind of authentication and authorization check.<p>This is becoming a trend with data breaches. Several of Krebs&#x27; other reports on behalf of security researchers were originally identified by (trivially) walking across object IDs on public URLs.<p>My cynical take is that Krebs couldn&#x27;t go public before this afternoon because First American wanted it to hit the news at an opportune time, then get ahead of it with their own messaging. Krebs got in touch with First American on Monday May 19th. The story is only just breaking now on a Friday afternoon at 5 pm; markets are conveniently closed for the weekend.<p>I expect them to issue a hollow PR statement about valuing security despite being unable to act on security reports until an investigative journalist threatens to go public.
评论 #20006242 未加载
评论 #20006280 未加载
评论 #20006156 未加载
raesene9almost 6 years ago
By the sounds of it, another breach from a well-known, not new web application security vulnerability, &quot;Insecure Direct Object Reference&quot;.<p>That vuln has been an explicit part of the OWASP Top 10 since 2007...<p>Unlike other common web app vulns (e.g. XSS SQLi) IDOR usually can&#x27;t be fixed by a development framework (e.g. ASP.Net or Rails), it needs app. specific coding for proper Authentication&#x2F;Authorization checks.
dmixalmost 6 years ago
&gt; He said anyone who knew the URL for a valid document at the Web site could view other documents just by modifying a single digit in the link.<p>Good thing he didn&#x27;t post this bug online after getting no response. I remember reading about someone who did that on an AT&amp;T website a while back and was sent to jail for simply incrementing an id number in the URL and talked about it on Twitter.
评论 #20007264 未加载
LinuxBenderalmost 6 years ago
That is an incredibly low friction interface to our documents. &#x2F;s<p>What are the odds they have access logs going back to 2003?
评论 #20005416 未加载
reilly3000almost 6 years ago
I just closed on my first house this week, and First American was of course my title company. I&#x27;ll be interested to see if my data is included in this breach settlement or not.<p>I did notice when I was reviewing my docs that they emailed links to unauthenticated copies of docs, but they were mostly public records so I didn&#x27;t think twice about it.<p>So they have my Name, address, email, SSN, copy of ID, copy of check from my bank with account&#x2F;routing on it and much more, all in the open apparently.<p>I just went through an SSO implementation with a small team for a large user base. It was a bigger project than we had anticipated, but nonetheless manageable. I can&#x27;t fathom that a financial institution of that scale could be that lax with basic security. Wouldn&#x27;t their systems be subject to some regulation and require some kind of audit on a regular basis? Is this a failure of auditing systems, as well as internal security or even basic IT?
JimmyDuganalmost 6 years ago
Programmers fault? Audits fault? Securities fault? Pentesters fault? It fault?<p>Listen until C-level funds these programs properly and security is taken seriously by all issues like this will forever be in the news.<p>I would be willing to bet their security like most have a long list of security gaps they cant get fixed because resource issues just hope they documented or it could fall on them.<p>Most coding classes just teach how to make things work in Mister Roger&#x27;s world. Secure coding is an elective! Most run the DevOps model instead SecDevOps and only involve security after it is ready to go into production no matter what flaws security finds.<p>Why are black box pentests still taking place? Because company required to have pentest but really do not want testers to find things. Their goal is not to improve security rather check that box ... we had a pentest.<p>C-level, this keep the lights on budget you give Security&#x2F;IT is costing you more than properly funding us! Oh yeah you put that $ into cyber insurance! Lol let&#x27;s see how well that works.
评论 #20029535 未加载
PatrolXalmost 6 years ago
Class Action Lawsuit Filed: <a href="https:&#x2F;&#x2F;finance.yahoo.com&#x2F;news&#x2F;first-class-action-lawsuit-filed-110000081.html" rel="nofollow">https:&#x2F;&#x2F;finance.yahoo.com&#x2F;news&#x2F;first-class-action-lawsuit-fi...</a>
JimmyDuganalmost 6 years ago
I see a lot of comments on sequential as the issue. Really is that the issue?<p>Not the fact that John Doe can get to John Doe2 stuff without authenticating? WTF<p>Sequential or not if no auth I can run a scanner and get it all so what the hell does that have to do with the price of tea in China?
zeroDivisiblealmost 6 years ago
I like how this news was posted on Friday afternoon before the Memorial Day weekend.
评论 #20007074 未加载
jammygitalmost 6 years ago
Where does one go to learn how to not cause this one day?
评论 #20007104 未加载
JimmyDuganalmost 6 years ago
Lol everyone fights security and it is way under funded so can only get like 1 out of 100 risks fixed but must be securities fault.
gesmanalmost 6 years ago
&quot;First American has learned of a design defect in an application that made possible unauthorized access to customer data. At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information...&quot;<p>Who is coming up with these statements?<p>If you kept royally screwing something for years that you claimed to be your &quot;highest priority&quot; - then what can one expect from your normal lines of business?
Nicksilalmost 6 years ago
&gt;At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information.<p>is such a meme.<p>Things will continue this way until there are serious repercussions for entities carelessly handling data.
评论 #20005732 未加载
评论 #20005496 未加载
snovv_crashalmost 6 years ago
At some point people will realise that holding large quantities of sensitive information is a liability, not an asset. Mindsets are slowly changing in this direction already.<p>The chickens will continue to come home to roost until people treat digital security as seriously as physical security.
评论 #20005566 未加载
评论 #20005950 未加载
评论 #20005545 未加载
评论 #20005590 未加载
评论 #20005781 未加载
评论 #20005542 未加载
评论 #20006705 未加载
评论 #20006424 未加载
wyxuanalmost 6 years ago
It seems that the stock price (under the ticker FAF) hasn&#x27;t suffered very much. This was revealed on 5&#x2F;19, and the response has been tepid.There isn&#x27;t likely going to be very much backlash on the stock, unfortunately.
评论 #20005379 未加载
评论 #20005482 未加载
评论 #20005320 未加载
评论 #20005629 未加载
评论 #20005323 未加载