Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

51–60 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#51

Earlier quoted context omitted.

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay.

The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved on.

It's more a problem with their reckless growth over the last decade than anything. (ed) Due diligence is obviously lacking, but I can personally attest that nobody in senior leadership there willfully ignores matters of security once it becomes known.

Re: Cybersecurity Incident Involving Consumer Information

#52
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

Unverified cert too -_-

The plain domain yields a 404. Cert for me seems to be signed by amazon.

https://trustedidpremier.com/

Re: Cybersecurity Incident Involving Consumer Information

#53
post #20

Earlier quoted context omitted.

Well, they try to find and convict the hackers, of course. Or did you mean the companies like Equifax, or Target, or Home Depot that are the victims of the break-ins?

They may have meant the actual victims, in this case 146,000,00 Americans.

Why do you think Equifax (or Home Depot, or Target) is any less of a victim here?

Re: Cybersecurity Incident Involving Consumer Information

#54

> Equifax has established a dedicated website, www.equifaxsecurity2017.com, to help consumers determine if their information has been potentially impacted and to sign up for credit file monitoring and identity theft protection. Really? "We lost your info. Sign up for our credit monitoring service!"

What's terrible is companies using SSNs at all.

Re: Cybersecurity Incident Involving Consumer Information

#55
post #37

Earlier quoted context omitted.

Equifax can handle its internal management and operations however it wants. Externally, though, I want Equifax to have to pay a fine for every individual whose information was compromised. Identity theft can easily cause five figures worth of damage, so $10k per individual would be fair. Maybe as a warning shot we could lower this to... $1k? $100? That's the only way to properly align incentives so companies will pro…

I would not doubt a class action lawsuit results from this, and I'd be very surprised if Elizabeth Warren didn't pursue congressional action against them (although not officers of the company unfortunately).

And then I'll get six months of free credit monitoring from Equifax? Oh boy!!1!

More seriously, this is a breach big enough that Equifax should honestly no longer exist as a company. So call it $100/incident, and I'm happy. Other agencies would still exist, and, although they're just as terrible, it might get them to kick their asses into high gear to fix their security.

Re: Cybersecurity Incident Involving Consumer Information

#56
>Exploited a US website application vulnerability >The information accessed primarily includes names, Social Security numbers... credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed

Was all this data available and accessible through the same application? I wonder how likely it was something incredibly trivial, like SQL injection, or whether they were truly targeted and infiltrated

Re: Cybersecurity Incident Involving Consumer Information

#57
post #36
post #4

Earlier quoted context omitted.

It sounds like ssn is not fit for purpose. If the gov is going to issue a 'secret number ' why not a 2fa device?

The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…

Not only was SSN not intended to be a national id, it was explicitly not supposed to be a national id.

In the era when SSN was established, Nazi Germany and its emphasis on "papers, please" was on the public's mind. SSN was intended to be used solely for tax purposes, not as a form of national identity. There were legal constraints on when government agencies can even ask for SSN, limited to legitimate tax purposes. Sadly, these protections have been whittled down over time:

https://www.bloomberg.com/view/articles/2016-09-15/this-loop...

> Federal law is supposed to protect the privacy of your Social Security number from government inquiries -- but apparently that doesn’t extend to a check on whether you’ve paid back taxes and child support. In a decision with worrying implications for those who oppose a single national identification number, a divided federal appeals court has rejected a lawyer’s refusal to submit his Social Security number along with his renewal of Maryland bar membership.

> The state says it needs Social Security numbers to make sure lawyers’ child support and taxes are up to date. The court’s majority said that was enough to fit the Social Security number under the federal law that allows states to use your number for tax purposes. That definition is so loose that it enables states to ask for your Social Security number pretty much whenever they want -- even when their records have been hacked.

Really, the government should make it possible for citizens to create an arbitrary number of different tax ids (SSNs), as many as they want. One for every firm they do business with, one for every employer, and so on.

Re: Cybersecurity Incident Involving Consumer Information

#58

Earlier quoted context omitted.

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

If that were the case, then who approved the acquisition? Who did due diligence on it?

Suddenly letting a bunch of untrusted, poorly audited code run on your infrastructure is itself a massive security breach. And even that doesn't explain how data was extracted for two months with no one noticing.

Re: Cybersecurity Incident Involving Consumer Information

#60
post #52

Earlier quoted context omitted.

Unverified cert too -_-

The plain domain yields a 404. Cert for me seems to be signed by amazon. https://trustedidpremier.com/

What I mean to say is it's not validated* They should have hosted this on a domain associated with the company and validated the cert with the business
Post reply on HN