Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

111–120 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#112
post #62

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Anyone know if there's a way to get your free credit report if you can't answer the questions for the free one? The computer says no, and the phone number just sends a letter that says no. I tried to to buy one from my bank, but as far as I can tell they only sell subscriptions...

Each of the credit reporting agencies has a process for requesting your credit report by snail mail. The form is hidden away on the various websites, but it has generally worked for me when the online form didn't work (it turns out another person's delinquent loans and CCs were in the report that they were using to test that it was me).

Not as free, since you need to buy envelopes / print the forms / photocopy your ID / get stamps / wait X weeks, but as free as it gets when the online system doesn't work.

Re: Cybersecurity Incident Involving Consumer Information

#113
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Exactly.

Eve lies to bob, and tells Bob she's Alice. Bob asks Claire, who says Yes, that's Alice." Bob gives Eve money, and Eve runs off.

This should not be Alice's fault, responsibility to solve, or problem to deal with. It is, because Bob is much, much more politically powerful than he ought to be.

Re: Cybersecurity Incident Involving Consumer Information

#114

Earlier quoted context omitted.

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

We don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If yo…

This so much. The stream of corporations passing the buck into a black hole of irresponsibility needs to end now. If people arent held responsible, they will continue to make these failings without pause. I hope everyone is writing their legislators and congresspeople right now. They listen more than even my disillusioned self thought. The just might have bigger incentives to act otherwise. But if they dont know, they cant even choose to be corrupt or not, they are ignorant by proxy. Communicate to your leaders, and remember their response when you vote.

Re: Cybersecurity Incident Involving Consumer Information

#115
post #30

> Credit reporting agencies are one of the greatest/worst rackets in the modern financial system Can someone notify me when the class action has been initiated?

If you want to win big, initiate it. Members of the class are likely to get something stupid like free credit monitoring from Equifax.

They are already offering exactly that. https://www.equifaxsecurity2017.com/

Re: Cybersecurity Incident Involving Consumer Information

#116

Earlier quoted context omitted.

So if an identity thief has enough of my information to potentially open a new line of credit, wouldn't they also have enough information to reverse the freeze? In other words, is a freeze enough to stop new accounts from being created?

You get a unique long pin code when you freeze the account. You need that to unfreeze it. There is some "recovery" procedure, I think you need a notary or something

And that unique long pin definitely isn't stored in plaintext in the next column over in their database, right?

Re: Cybersecurity Incident Involving Consumer Information

#117
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

I also noted that it asked for the last 6 digits of your social. Could be they need more digits to avoid duplicates, but I've never heard anyone ask for 6 digits. Usually it's just the 4.

Honestly, they should have used a subdomain off of Equifax.com.

Re: Cybersecurity Incident Involving Consumer Information

#118
post #69

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity.

Here in the US, our Social Security Act said exactly the same thing.

Guess what. It got used as a proof of identity.

Re: Cybersecurity Incident Involving Consumer Information

#120
post #107

Hm, I tried using their tool to see if I've been impacted: https://www.equifaxsecurity2017.com/potential-impact/ Which says it would tell me if I'm likely impacted, but instead it just gives a date where I can enroll in some free product, but no info on whether I'm likely compromised. Anyone have a workaround? This is important to anyone that wants to identify if they've been "pwned."

I got the same page, but then I tried putting in a fake name and got:

> Thank You

> Based on the information provided, we believe that your personal information was not impacted by this incident.

So if you just get the enrollment date, I think that means you’re affected.

Post reply on HN