Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

91–100 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#91
post #69

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…

> This is not proof of identity.

What is it then?

I've seen it used as a quasi-password by car hire companies to access driving license history.

Re: Cybersecurity Incident Involving Consumer Information

#92
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

And trustedidpremier.com was registered a week ago. https://whois.domaintools.com/trustedidpremier.com

TrustedID is an identity protection company that's been around for awhile (many companies use them as the contracted company to do credit monitoring after a breach). TrustedID is actually owned by Equifax (who were just hacked.. irony), and so my guess is that "TrustedID Premiere" is a newly created offering from Equifax/TrustedID to deal specifically with this major breach.

Re: Cybersecurity Incident Involving Consumer Information

#93
Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank.

Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit reporting agencies inflicting this upon Alice. BigBank is the victim who lost money, and BigBank bears the responsibility for making the mistake of giving out a loan in Alice's name. The Fraudster committed a crime against BigBank, not against Alice. It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice.

The idea that Alice was victimized by Fraudster is a concept being perpetuated by the credit reporting agencies as a way to absolve themselves of responsibility, and place the burden upon the consumer, and to avoid realistic identity-verifiction which might slow or complicate the practice of issuing large amounts of debt to the general public.

Re: Cybersecurity Incident Involving Consumer Information

#94

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

So if an identity thief has enough of my information to potentially open a new line of credit, wouldn't they also have enough information to reverse the freeze?

In other words, is a freeze enough to stop new accounts from being created?

Re: Cybersecurity Incident Involving Consumer Information

#95
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

And trustedidpremier.com was registered a week ago. https://whois.domaintools.com/trustedidpremier.com

Well, yes, this was in response to this incident. While they're just making a public statement now, we know from their own press release that the breach occurred in May.

Regardless, it's certainly prudent to be wary of these sites since they're pretty indistinguishable from phishing sites.

Re: Cybersecurity Incident Involving Consumer Information

#96
post #24

Earlier quoted context omitted.

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

I don't understand this. Equifax claims they just leaked my SSN, Drivers License, and other pertinent data to everybody. How would they possibly confirm that I am the one lifting the 'freeze'?

When you get your account frozen they provide a PIN to unlock.

Re: Cybersecurity Incident Involving Consumer Information

#97
post #57
post #36

Earlier quoted context omitted.

The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…

Not only was SSN not intended to be a national id, it was explicitly not supposed to be a national id. In the era when SSN was established, Nazi Germany and its emphasis on "papers, please" was on the public's mind. SSN was intended to be used solely for tax purposes, not as a form of national identity. There were legal constraints on when government agencies can even ask for SSN, limited to legitimate tax purposes.…

http://www.nytimes.com/1998/07/26/weekinreview/the-nation-no...

Re: Cybersecurity Incident Involving Consumer Information

#98
post #91
post #69

Earlier quoted context omitted.

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…

> This is not proof of identity. What is it then? I've seen it used as a quasi-password by car hire companies to access driving license history.

They can use it as a key to the database without treating it as proof of identity.

(I don't know that they do, it's just that the one doesn't necessarily follow from the other)

Re: Cybersecurity Incident Involving Consumer Information

#99

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

At this stage, if you have to pay the company that leaks your own data to prevent it from harming you, it starts to sound like protection racket.

Re: Cybersecurity Incident Involving Consumer Information

#100

Earlier quoted context omitted.

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

[deleted]
Post reply on HN