Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

1–10 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#2
> approximately 143 million U.S. consumers.

This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed).

Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen? Surely it's not just the one agency (SSA) that would need to make the change, but multiple agencies would need to coordinate the change?

(And of course, I would be personally responsible for informing my banks, brokerages, loan agencies, etc of my new SSN)

Does anyone have insight into how this could work?

Re: Cybersecurity Incident Involving Consumer Information

#3
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

So half the US population? Ugh.

Re: Cybersecurity Incident Involving Consumer Information

#4
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

It sounds like ssn is not fit for purpose.

If the gov is going to issue a 'secret number ' why not a 2fa device?

Re: Cybersecurity Incident Involving Consumer Information

#6
I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to.

It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you need to allow access to your credit (credit check for rent, taking out a loan, etc), you can temporarily lift your credit freeze for a small fee. The fees associated with this are going to be much cheaper than any of the professional "identify protection" services that exist out there, and the freeze is significantly more effective at protecting you.

When a company leaks your social security number and personal details, which almost certainly will happen at some point if it hasn't already, then opening fraudulent accounts in your name isn't the only risk you face, but it's an obvious and dangerous possibility that can ruin you financially or make you spend a considerable amount of time and energy fixing the situation.

For every person in the US with kids, I also strongly suggest that you freeze their credit as well. There's no good reason for your 13 year old to take out a loan, but identity thieves don't care about how old their victim is.

Re: Cybersecurity Incident Involving Consumer Information

#7

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

You've sold me, now tell me how to do it

Re: Cybersecurity Incident Involving Consumer Information

#8
Lovely. I just had to give Equifax a bunch of my own info after having my identity stolen[0]. When dealing with this, I was amazed at how technically inept all three agencies seem to be. Not to mention the extent to which they use SSN and other PII to "verify" during phone calls, and try to sell their credit monitoring services to you. This sort of thing should be provided for free by these companies if they are going to be managing such valuable data.

[0] https://chrxs.net/articles/2017/03/23/responding-to-identity...

Re: Cybersecurity Incident Involving Consumer Information

#10
post #4
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

It sounds like ssn is not fit for purpose. If the gov is going to issue a 'secret number ' why not a 2fa device?

I really wish they would issue something like this. Or put a smartcard in my driver's license (I'm sure there are privacy implications to this though).
Post reply on HN