Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

81–90 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#82
post #38

> Equifax discovered the unauthorized access on July 29 Well over a month later and they're just now getting around to telling people about a security breach that could affect almost half of all Americans... How is this ok/legal?

Discovering a breach is only a fraction of what has to happen before customers/public should be notified of said breach. It's not very helpful to anyone if you put out a press release that just says "we discovered a breach but have no idea who, if anyone, was affected, we have no idea what was stolen, and we have no idea who did it." There have to be investigations that happen prior to any of that being known/released. Investigations to find this type of stuff out usually takes months, and typically involves the FBI or other agencies, which sometimes will actually ask you to keep news of the breach quiet if it might help them track down the perpetrators. You also want time to fix the issue before you go tell the entire world that there's a hole in your security.

I work in cybersec and I would actually say that under 1.5 months from discovery of unauthorized access to releasing this press release (and already having the equifaxsecurity2017 website up and running) is astonishingly fast work.

Re: Cybersecurity Incident Involving Consumer Information

#83

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

I can't agree with this more. I was the victim of identity theft many years ago. I my case the data leaked from an employee at my company's payroll dept! There was nothing I could have done to prevent it. Anyway I did this many years ago and have not worried about it since. There is some small hassle because people run credit checks for weird reasons that have nothing to do with trying to get a loan or line of credit. For instance when I got promoted to a certain level at my last company they ran one, and while they didn't run them when I got hired, I think later they started doing them as part of "background checks" for all new hires. The other hassle is sometimes the credit agencies change the way you "unfreeze" and I've had some problems with that, or the people running the check don't actually know which of the three credit agencies they are using. However for the once every four or five years hassle it is definitely worth the piece of mind for me. In many cases you can "temporarily" revoke it for a week or 10 days.

Re: Cybersecurity Incident Involving Consumer Information

#87
post #47
post #29

Earlier quoted context omitted.

I mean the companies like Equifax. Is there nothing illegal about being careless enough to leak this much important information to hackers? I personally think they should be held accountable.

Accountable for what? That they're a target for hackers, who managed to break into their network? How is that careless? There's no such thing as perfect security.

This case seems a little different in that it's pretty difficult to not have your personal information in their system.

You roll in to Target or Home Depot, you decide to pay with a check, card or cash. You decide to give them your information or not. You decide if you want to go back after they mismanage your information. Can you opt out of Equifax's business and still get credit or loans? Can you even opt out at all?

Re: Cybersecurity Incident Involving Consumer Information

#89
>Equifax said that, it had hired a cybersecurity firm to conduct a review to determine the scale of the invasion.

I think most people are unaware of the depth of data Equifax has on them, beyond simple credit scores (e.g. health information).

Which makes the above quote from the article even more unconscionable. There should be no need for an outside firm to figure out what happened. They should have in-house expertise that is unmatched (although third-party audits ahead of time would be wise).

Post reply on HN