all messages for Emacs-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
From: Richard Stallman <rms@gnu.org>
To: emacs-devel@gnu.org
Subject: to patch two-month-old bug led to massive Equifax breach
Date: Thu, 14 Sep 2017 16:52:13 -0400	[thread overview]
Message-ID: <E1dsb7N-0003KV-K7@fencepost.gnu.org> (raw)

------- Start of forwarded message -------
X-Spam-Status: No, score=0.8 required=5.0 tests=BAYES_50,RCVD_IN_DNSWL_NONE,
	RP_MATCHES_RCVD,URIBL_BLOCKED autolearn=disabled version=3.3.2
Date: Wed, 13 Sep 2017 20:31:01 -0700
To: privacy-list@vortex.com
Content-Disposition: inline
Message-ID: <mailman.7837.1505359862.1434.privacy@vortex.com>
From: PRIVACY Forum mailing list <privacy@vortex.com>
Subject: [ PRIVACY Forum ] Failure to patch two-month-old bug led to massive
 Equifax breach
Reply-To: PRIVACY Forum mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="us-ascii"


Failure to patch two-month-old bug led to massive Equifax breach

https://arstechnica.com/information-technology/2017/09/massive-equifax-breach-caused-by-failure-to-patch-two-month-old-bug/

  	Thursday's disclosure strongly suggests that Equifax failed to
	update its Web applications, despite demonstrable proof the
	bug gave real-world attackers an easy way to take control of
	sensitive sites.  An Equifax representative didn't immediately
	respond to an e-mail seeking comment on this possibility. As
	Ars warned in March, patching the security hole was labor
	intensive and difficult, in part because it involved
	downloading an updated version of Struts and then using it to
	rebuild all apps that used older, buggy Struts versions. Some
	websites may depend on dozens or even hundreds of such apps,
	which may be scattered across dozens of servers on multiple
	continents.

 - - -

- --Lauren--
Lauren Weinstein (lauren@vortex.com): https://www.vortex.com/lauren 
Lauren's Blog: https://lauren.vortex.com
Google Issues Mailing List: https://vortex.com/google-issues
Founder: Network Neutrality Squad: https://www.nnsquad.org 
         PRIVACY Forum: https://www.vortex.com/privacy-info
Co-Founder: People For Internet Responsibility: https://www.pfir.org/pfir-info
Member: ACM Committee on Computers and Public Policy
Google+: https://google.com/+LaurenWeinstein
Twitter: https://twitter.com/laurenweinstein
Tel: +1 (818) 225-2800
- --- Impeach Trump ---
_______________________________________________
privacy mailing list
https://lists.vortex.com/mailman/listinfo/privacy
------- End of forwarded message -------

-- 
Dr Richard Stallman
President, Free Software Foundation (gnu.org, fsf.org)
Internet Hall-of-Famer (internethalloffame.org)
Skype: No way! See stallman.org/skype.html.




                 reply	other threads:[~2017-09-14 20:52 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=E1dsb7N-0003KV-K7@fencepost.gnu.org \
    --to=rms@gnu.org \
    --cc=emacs-devel@gnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/emacs.git
	https://git.savannah.gnu.org/cgit/emacs/org-mode.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.