Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

11–20 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#11

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

You've sold me, now tell me how to do it

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state.

https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo...

https://www.transunion.com/credit-freeze/place-credit-freeze

https://www.experian.com/freeze/center.html

Re: Cybersecurity Incident Involving Consumer Information

#12
> Equifax has established a dedicated website, www.equifaxsecurity2017.com, to help consumers determine if their information has been potentially impacted and to sign up for credit file monitoring and identity theft protection.

Really? "We lost your info. Sign up for our credit monitoring service!"

Re: Cybersecurity Incident Involving Consumer Information

#13
post #4
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

It sounds like ssn is not fit for purpose. If the gov is going to issue a 'secret number ' why not a 2fa device?

The real problem is that SSNs are used double-duty as an identifier and authentication mechanism.

This has been predictably bad for security.

Re: Cybersecurity Incident Involving Consumer Information

#14

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

I recently did this and highly recommend IdentityTheft.gov for assistance. It has tons of great resources/guidance for dealing with identity theft and other credit issues.

https://www.identitytheft.gov/

Re: Cybersecurity Incident Involving Consumer Information

#16

> Equifax has established a dedicated website, www.equifaxsecurity2017.com, to help consumers determine if their information has been potentially impacted and to sign up for credit file monitoring and identity theft protection. Really? "We lost your info. Sign up for our credit monitoring service!"

Yep. All three do this and it drives me nuts. This instance is especially terrible given that Equifax is the breached service.

Re: Cybersecurity Incident Involving Consumer Information

#17
post #4
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

It sounds like ssn is not fit for purpose. If the gov is going to issue a 'secret number ' why not a 2fa device?

Estonia does this. https://en.wikipedia.org/wiki/Estonian_ID_card

Re: Cybersecurity Incident Involving Consumer Information

#19
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity.

It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a business or process that uses by SSN instead of proper two-factor authentication (...a large number of credit-based companies and financial institutions, sadly) my trust in them simply plummets, the same as it would for the login I use on less secure forum sites.

Re: Cybersecurity Incident Involving Consumer Information

#20
post #9

Is anyone being punished for all of the massive security breaches which appear to be happening on a nearly daily basis?

Well, they try to find and convict the hackers, of course. Or did you mean the companies like Equifax, or Target, or Home Depot that are the victims of the break-ins?
Post reply on HN