How did this breach occur

Assignment Help Basic Computer Science
Reference no: EM134003763

Assignment:

In 2019, one of the largest data breaches in history occurred when First American Financial Corporation, a real estate title insurance company, exposed over 885 million records on its public website. Included in these records was information such as Social Security numbers, bank account information, images of driver's licenses, mortgage statements, tax documents, and wire transfer records dating all the way back to 2003. The company was not aware of the problem until it was notified by security expert Brian Krebs, an outside source.

A real estate developer outside of FAF first noticed this concern when they found that anyone who knew the URL for a valid document could then access any other document simply by changing a number in the URL. The company's website, firstam.com, was leaking hundreds of millions of private documents not intended to be viewed by just any user. This means that any individual who had previously been emailed a link from FAF could possibly gain access to a plethora of sensitive and private documents. No authentication was required in order to access these documents, nor were they protected in any other way. This left a lot of personal and private information exposed for those with malicious intent to use in nefarious ways, for example, identity theft.

When FAF was notified of the breach, it shut down its website and immediately conducted an internal review. The initial findings noted that there was a "design defect in an application that made possible unauthorized access to customer data" (Newman, 2019). The identified defect could be referred to as a business logic flaw, which is "a category of vulnerabilities specific to an application and business domain . . . [It] allows an attacker to misuse the application by circumventing the business rules of the application" (Conikee, 2019). Only a user with an appropriate link would be able to access these documents. However, a user would not be asked to verify their identity. Therefore, access was easy and unauthenticated.

  • How did this breach occur? Briefly summarize the incident.
  • Which pillars of the CIA triad were explicitly violated, given the scenario?
  • What kinds of security controls could First American Financial Corporation have put in place to defend against this kind of data breach? Why?

Reference no: EM134003763

Questions Cloud

Role of regulatory agencies in the health care industry : What is the role of regulatory agencies in the health care industry? How does this agency manage regulations?
How can case managers effectively support clients facing : How can case managers effectively support clients facing setbacks or new challenges during the maintenance phase of the change process?
Describe the target population : Describe the target population. Describe the role of the nurse advocate for the target population for the healthcare program you selected.
How someone plan to incorporate commitment to social change : How can someone plan to incorporate a commitment to social change into their DNP program of study and professional practice?
How did this breach occur : How did this breach occur? Briefly summarize the incident. Which pillars of the CIA triad were explicitly violated, given the scenario?
What would you do differently to improve this outcome : What would you do differently to improve this outcome? Describe at least three benefits that collaboration with stakeholders may provide regarding patient care.
Professional organization Registered Nurses of Ontario : Describe the professional organization Registered Nurses of Ontario and the resources that are available to the public and to members only.
Describe how supplements are regulated : Describe how supplements are regulated. Describe risk factors and nutritional implications of food insecurity.
Why do you think that diadochokinetic rates use repetition : Why do you think that diadochokinetic rates use the repetition of [p?], [t?], and [k?] as opposed to other sounds or sound combinations?

Reviews

Write a Review

Basic Computer Science Questions & Answers

  Identifies the cost of computer

identifies the cost of computer components to configure a computer system (including all peripheral devices where needed) for use in one of the following four situations:

  Input devices

Compare how the gestures data is generated and represented for interpretation in each of the following input devices. In your comparison, consider the data formats (radio waves, electrical signal, sound, etc.), device drivers, operating systems suppo..

  Cores on computer systems

Assignment : Cores on Computer Systems:  Differentiate between multiprocessor systems and many-core systems in terms of power efficiency, cost benefit analysis, instructions processing efficiency, and packaging form factors.

  Prepare an annual budget in an excel spreadsheet

Prepare working solutions in Excel that will manage the annual budget

  Write a research paper in relation to a software design

Research paper in relation to a Software Design related topic

  Describe the forest, domain, ou, and trust configuration

Describe the forest, domain, OU, and trust configuration for Bluesky. Include a chart or diagram of the current configuration. Currently Bluesky has a single domain and default OU structure.

  Construct a truth table for the boolean expression

Construct a truth table for the Boolean expressions ABC + A'B'C' ABC + AB'C' + A'B'C' A(BC' + B'C)

  Evaluate the cost of materials

Evaluate the cost of materials

  The marie simulator

Depending on how comfortable you are with using the MARIE simulator after reading

  What is the main advantage of using master pages

What is the main advantage of using master pages. Explain the purpose and advantage of using styles.

  Describe the three fundamental models of distributed systems

Explain the two approaches to packet delivery by the network layer in Distributed Systems. Describe the three fundamental models of Distributed Systems

  Distinguish between caching and buffering

Distinguish between caching and buffering The failure model defines the ways in which failure may occur in order to provide an understanding of the effects of failure. Give one type of failure with a brief description of the failure

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd