Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

61–70 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#61

Earlier quoted context omitted.

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

I find it difficult to reconcile your second and third paragraphs.

I guess choosing not to prioritize security (vs profit or whatever) when making acquisitions is different than just ignoring it entirely.

Re: Cybersecurity Incident Involving Consumer Information

#62

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Anyone know if there's a way to get your free credit report if you can't answer the questions for the free one?

The computer says no, and the phone number just sends a letter that says no. I tried to to buy one from my bank, but as far as I can tell they only sell subscriptions...

Re: Cybersecurity Incident Involving Consumer Information

#63
post #4
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

It sounds like ssn is not fit for purpose. If the gov is going to issue a 'secret number ' why not a 2fa device?

Public-key crypto has been around since the late 1970s. Smart cards have been around since the 1990s. Two decades is nowhere near enough time for these sorts of changes to go through, you have to wait for all the past generation's lawmakers to retire/die and be replaced. Getting financial institutions to adopt new things that don't directly make them money is even harder.

Re: Cybersecurity Incident Involving Consumer Information

#64

Oh nice. A company that does nothing but collect personal information. I’m already in their identity protection program, so I'm a little nonplussed at this.

Are you extremely surprised at this, or not at all? Just from context, I can't quite decide which it is.

Re: Cybersecurity Incident Involving Consumer Information

#65

Earlier quoted context omitted.

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

We don't know if this has anything to do with any acquisitions - this is a conjecture, at best.

At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in.

Allowing data to slip out is negligent. If you're in the army, or the intelligence community, you get punished for this. It's about time the private sector felt some sort of accountability.

Re: Cybersecurity Incident Involving Consumer Information

#66
post #53

Earlier quoted context omitted.

They may have meant the actual victims, in this case 146,000,00 Americans.

Why do you think Equifax (or Home Depot, or Target) is any less of a victim here?

I leave my home with a house sitter. The house sitter throws a kegger, and his guests cause six figures worth of property damage, including stealing the house sitter's laptop.

Who are all the criminal parties here?

Re: Cybersecurity Incident Involving Consumer Information

#67
post #62

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Anyone know if there's a way to get your free credit report if you can't answer the questions for the free one? The computer says no, and the phone number just sends a letter that says no. I tried to to buy one from my bank, but as far as I can tell they only sell subscriptions...

You could see if Credit Karma works. I think it is mostly a free interface to Trans Union though.

Re: Cybersecurity Incident Involving Consumer Information

#68
post #38

> Equifax discovered the unauthorized access on July 29 Well over a month later and they're just now getting around to telling people about a security breach that could affect almost half of all Americans... How is this ok/legal?

The law gives them time to try to fix the problem before telling every hacker in the world about it.

Re: Cybersecurity Incident Involving Consumer Information

#69
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that:

This is not proof of identity.

Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such.

SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could also be brought about through legislation making it not legal to ask for SSN as proof of ID (i.e. can only ask for SSN when required for the purposes it is intended for), but legislating such things is likely even further from your culture.

Re: Cybersecurity Incident Involving Consumer Information

#70

If it's online, it will be hacked and exposed. The new reality! Let's just try to limit what info we give to companies, knowing it will be leaked soon or later.

The problem with this is the major reporting bureaus source their information from banks and credit card companies. The data gets out of their hands quickly, and you don't have the option to protect it in the first place.

My opinion is that the only real solution is to internalize the externalities via fines, taxes, or regulation.

Post reply on HN