The thread installs Equifax as a case in which a 48-hour patch order, a mass email, and a vulnerability scan were allowed to count as one control on a dispute portal that could reach files of people who cannot opt out. The unresolved question is which repair, required in March 2017, would have turned CVE-2017-5638 into a non-event for those files. Applying Struts 2.3.32 or 2.5.10.1 on ACIS is one rule: that is S2-045, and TransUnion and Experian did the equivalent within days. An inventory the scan cannot miss is a different first rule: Equifax's 15 March scan found nothing. Keeping a dispute portal from querying 48 other databases is a third: GAO and the House report already name the hop. Inspecting the encrypted channel (the expired certificate) is a fourth. Those are not substitutes. A patched portal that still talks to 48 unsegmented databases still dumps Social Security numbers after the next CVE. A segmented network with the Struts instance still unpatched still gives remote code execution on the portal. Credit monitoring after the fact does not pick. GAO-18-559, the FTC complaint, the House staff report, Smith's 3 October testimony, and the Senate subcommittee already record all four. They do not say which one, required when the CERT notice arrived, would have kept a dispute form from becoming 145 million Social Security numbers.
thread · conversion
Conversion is a discussion-search product. Author dispositions remain author-owned; thread consensus cannot infer them.
conversion named_unresolved