* to patch two-month-old bug led to massive Equifax breach
@ 2017-09-14 20:52 Richard Stallman
0 siblings, 0 replies; only message in thread
From: Richard Stallman @ 2017-09-14 20:52 UTC (permalink / raw)
To: emacs-devel
------- Start of forwarded message -------
X-Spam-Status: No, score=0.8 required=5.0 tests=BAYES_50,RCVD_IN_DNSWL_NONE,
RP_MATCHES_RCVD,URIBL_BLOCKED autolearn=disabled version=3.3.2
Date: Wed, 13 Sep 2017 20:31:01 -0700
To: privacy-list@vortex.com
Content-Disposition: inline
Message-ID: <mailman.7837.1505359862.1434.privacy@vortex.com>
From: PRIVACY Forum mailing list <privacy@vortex.com>
Subject: [ PRIVACY Forum ] Failure to patch two-month-old bug led to massive
Equifax breach
Reply-To: PRIVACY Forum mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="us-ascii"
Failure to patch two-month-old bug led to massive Equifax breach
https://arstechnica.com/information-technology/2017/09/massive-equifax-breach-caused-by-failure-to-patch-two-month-old-bug/
Thursday's disclosure strongly suggests that Equifax failed to
update its Web applications, despite demonstrable proof the
bug gave real-world attackers an easy way to take control of
sensitive sites. An Equifax representative didn't immediately
respond to an e-mail seeking comment on this possibility. As
Ars warned in March, patching the security hole was labor
intensive and difficult, in part because it involved
downloading an updated version of Struts and then using it to
rebuild all apps that used older, buggy Struts versions. Some
websites may depend on dozens or even hundreds of such apps,
which may be scattered across dozens of servers on multiple
continents.
- - -
- --Lauren--
Lauren Weinstein (lauren@vortex.com): https://www.vortex.com/lauren
Lauren's Blog: https://lauren.vortex.com
Google Issues Mailing List: https://vortex.com/google-issues
Founder: Network Neutrality Squad: https://www.nnsquad.org
PRIVACY Forum: https://www.vortex.com/privacy-info
Co-Founder: People For Internet Responsibility: https://www.pfir.org/pfir-info
Member: ACM Committee on Computers and Public Policy
Google+: https://google.com/+LaurenWeinstein
Twitter: https://twitter.com/laurenweinstein
Tel: +1 (818) 225-2800
- --- Impeach Trump ---
_______________________________________________
privacy mailing list
https://lists.vortex.com/mailman/listinfo/privacy
------- End of forwarded message -------
--
Dr Richard Stallman
President, Free Software Foundation (gnu.org, fsf.org)
Internet Hall-of-Famer (internethalloffame.org)
Skype: No way! See stallman.org/skype.html.
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2017-09-14 20:52 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-09-14 20:52 to patch two-month-old bug led to massive Equifax breach Richard Stallman
Code repositories for project(s) associated with this external index
https://git.savannah.gnu.org/cgit/emacs.git
https://git.savannah.gnu.org/cgit/emacs/org-mode.git
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.