<The Connection Between Car Purchases and Data Breaches Explained>
Written on
On July 14, I will be delivering the closing keynote at the fifteenth Hackers On Planet Earth event in Queens, NY, and on July 20, I am set to speak at Chicago's Exile in Bookville.
In 2017, Equifax experienced a catastrophic data breach, exposing sensitive information on 148 million Americans, 15 million Britons, and 19,000 Canadians. This event created a lasting reservoir of personal data that could be misused for identity theft.
Equifax was aware that a breach was imminent. Not only did top executives sell their shares before the breach was disclosed, but they also disregarded numerous warnings from IT staff about vulnerabilities in their server security.
Following the breach, Equifax's situation deteriorated, leading to a series of subsequent breaches. Their systems were riddled with flaws, allowing multiple hacker groups to infiltrate various segments of their infrastructure repeatedly.
This situation echoes the issues faced by Boeing, where the disastrous 737 Max incidents were not just isolated failures but the culmination of a long history of neglect and poor safety practices within the aviation giant.
The parallels are striking: just as Boeing's 737 Max failures revealed deeper systemic issues, Equifax's breaches highlighted the fragility of their IT infrastructure. It’s akin to discovering that your home, which you believed was a secure investment, is actually a liability riddled with foundational problems.
Equifax isn't merely a corporation; it serves as a crucial part of the economic infrastructure. Initially, it operated as an entity that facilitated discrimination based on personal data, creating a framework that allowed for the denial of loans based on factors such as race and sexual orientation.
This practice evolved into a significant component of the credit industry, giving Equifax the power to impact lives with hastily compiled data that individuals had minimal rights to contest or access. The company became a behemoth through acquisitions, supported by lax antitrust regulations.
The chain of acquisitions led to an accumulation of tech debt that would be hard to eliminate. As Equifax integrated various systems, it created a patchwork of technologies that were increasingly fragile and susceptible to failure, a situation exacerbated by outdated programming languages and systems.
The British Library's analysis following its ransomware incident serves as a cautionary tale about tech debt and systemic vulnerabilities, demonstrating how institutions with a long history of accumulating tech debt are often the most susceptible to breaches.
Equifax's predicament was compounded by a series of mergers, resulting in a convoluted IT landscape that was difficult to manage securely. The quest for monopoly power made it less accountable, further emboldening negligence in addressing security vulnerabilities.
The executives at Equifax were aware of the impending crises but chose to ignore the warnings, understanding they had a safety net that protected them from the consequences of their failures.
Boeing faced a similar fate as it merged with other firms, leading to an increased complexity that was poorly managed. The focus shifted to financial gains, often at the expense of safety and security.
The underlying narrative of corporate America over the past several decades has been one of accumulating tech debt and merging into monopolistic entities while neglecting necessary investments in security infrastructure.
Last February, the emergence of Change Healthcare as a critical player in the American healthcare system was a stark reminder of how vulnerable our systems can be. When Change Healthcare suffered a ransomware attack, it crippled the ability to process prescriptions nationwide, highlighting the dangers of monopolistic practices.
UnitedHealthcare's aggressive strategy to dominate the market led to a precarious situation where personal health data was compromised, impacting the lives of millions. This incident tied back to a long history of mergers that prioritized growth over security.
Ticketmaster is another example of a company that grew through mergers, culminating in a recent breach that exposed personal data of 500 million users. These breaches are not isolated incidents but rather symptoms of a systemic problem within monopolistic companies.
As we pivot back to the automotive industry, CDK Global stands out as a monopolist in dealer management software. Their systems are essential for car purchases, yet they've faced significant security challenges, rendering many unable to complete transactions.
The narrative surrounding CDK mirrors the patterns seen in Equifax and other corporations. An executive's threats to eliminate competition through illegal collusion led to a landmark antitrust case, demonstrating the lengths to which these firms will go to maintain their power.
This struggle is emblematic of a larger issue within corporate America, where the drive for monopoly leads to inflated prices and compromised services, further eroding trust in the systems we depend on.
In a recent judgment, the 7th Circuit Court ruled in favor of CDK, allowing them to continue their monopolistic practices, which ultimately contributed to the vulnerability of the automotive purchasing process.
The implications of such rulings are profound, as they perpetuate an environment where companies prioritize profits over consumer safety and security. This creates a cycle of negligence that endangers millions.
In conclusion, the intricate web of mergers and the pursuit of market dominance have led to a reality where systemic failures are commonplace, and consumers bear the brunt of these corporate decisions. The inability to buy a car today reflects a deeper, more troubling issue within the corporate landscape.
Support me this summer on the Clarion Write-A-Thon and help raise money for the Clarion Science Fiction and Fantasy Writers’ Workshop!
For a more formatted version of this analysis, visit my blog: https://pluralistic.net/2024/06/28/dealer-management-software/#antonin-scalia-stole-your-car
Image: Cryteria (modified) https://commons.wikimedia.org/wiki/File:HAL9000.svg CC BY 3.0 https://creativecommons.org/licenses/by/3.0/deed.en