Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

131–140 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#132
post #29
post #20

Earlier quoted context omitted.

Well, they try to find and convict the hackers, of course. Or did you mean the companies like Equifax, or Target, or Home Depot that are the victims of the break-ins?

I mean the companies like Equifax. Is there nothing illegal about being careless enough to leak this much important information to hackers? I personally think they should be held accountable.

Putting aside the whole "punishing the victim" argument, the problem is that it's excruciatingly hard to draw a line between "being careless" and "you did everything right but it still wasn't enough", and thus it's really hard to punish someone for cybersecurity mistakes. I work in cybersec consulting, and it's certainly true that a large number of companies are simply not investing enough money/time/effort into cybersecurity protections, and are thus doing a disservice to their customers.

However, there are also plenty of companies that spend hundreds of millions of dollars, with massive cybersec departments devoted to protecting from breaches like this, doing pretty much everything they possibly can right, and they will still be hacked. Cybersecurity is incredibly difficult, incredibly expensive, and takes a really long time. And even if you get 99.999999% of your company completely impervious to attackers, it only takes that 0.0000001% of exposure to sink your ship. Cybersec is also constantly evolving, so it's nearly impossible to keep up with the latest attack vectors, etc.

Take the Target breach, for example: Target has a massive effort focused on cybersecurity. They actually have a cybersec research lab that some law enforcement agencies go to for help with cybersec issues. But the attack that hit them took them totally by surprise simply because it was a type of attack that hadn't really been considered, and thus was very very low on the radar (if there at all) when it came to protecting against it.

Now, companies in the US actually are held accountable (to an extent). Data breaches that result in HIPAA violations, for example, usually result in massive fines for companies. Violations of PCI-DSS will land you in hot water with the major payment card companies. Some states also have cybersec regulations that result in fines if you're found to be in violation of them during an audit. The problem, again, is that cybersec is constantly evolving and these regulations are years behind. The HIPAA cybersec requirements are actually pretty laughable, partly because of all the reasons listed above.

Re: Cybersecurity Incident Involving Consumer Information

#134
post #111

Doing some junky googling, estimates for how many Americans have a credit card sits in the ~160-180million range. In other words, when they say "143 million US customers" they really mean "the vast majority of Americans with a credit card". Astounding.

About half of the country.

Re: Cybersecurity Incident Involving Consumer Information

#135
post #107

Hm, I tried using their tool to see if I've been impacted: https://www.equifaxsecurity2017.com/potential-impact/ Which says it would tell me if I'm likely impacted, but instead it just gives a date where I can enroll in some free product, but no info on whether I'm likely compromised. Anyone have a workaround? This is important to anyone that wants to identify if they've been "pwned."

A website registed a month ago with a simple DV certificate. Either the gentlemen at equifax are grossly incompetent, either this is a phishing website.

Re: Cybersecurity Incident Involving Consumer Information

#137
Fear not. You can check to see if you were affected by visiting their site and giving them more personal data:

https://www.equifaxsecurity2017.com

/s

Maybe it doesn't matter much, since they've likely already got it. But, it feels a bit too soon.

An interesting side-note: That domain was registered about two weeks ago on 8/22/2017. Whois reveals not a single pointer to Equifax (e.g. equifax.com email address, etc.). It shows only DNStination Inc., and so is effectively private.

When you click the "Enroll" link, then "Begin Enrollment" button, it takes you to https://trustedidpremier.com, which was registered on 8/28/2017, using a different registrar (Amazon, with Whois Privacy). There's not even a reference to Equifax in the domain itself.

As of today, someone registered equifaxsecurity2018.com with a private (this time, Domains By Proxy) registration. Given the timing and the fact that this is a different registrar from the original, it's a good bet that's not Equifax. Or is it? Who knows?

And SSL-wise, these don't even appear to be using extended validation certs (FWIW). At least one is an Amazon cert, free to anyone who hosts on AWS.

They are virtually training people to be phished and creating another potential disaster with all of these additional domains, private registrations, etc.

Re: Cybersecurity Incident Involving Consumer Information

#138
post #62

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Anyone know if there's a way to get your free credit report if you can't answer the questions for the free one? The computer says no, and the phone number just sends a letter that says no. I tried to to buy one from my bank, but as far as I can tell they only sell subscriptions...

credit karma

Re: Cybersecurity Incident Involving Consumer Information

#139
post #131

> The company has found no evidence of unauthorized activity on Equifax’s core consumer or commercial credit reporting databases. Oh good, sounds like Equifax's valuable data is safe, it's just that of their unwilling 'customers' that leaked.

Oh good, sounds like Equifax's valuable data is safe, it's just that of their unwilling 'customers' that leaked.

Don't worry, for $9.99 a month they'll help you clean the mess they made. I am being sarcastic, but I wouldn't be surprised at their audacity.

Re: Cybersecurity Incident Involving Consumer Information

#140
post #121
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Bigbank is the only one in your scenario that actually has monetary loss since they lent out the money and most likely will never get it back. In identity theft, the company has the financial loss. FBI won't investigate unless its over 250k in losses as well.

Pretty twisted world where provable financial loss is the only or main measure.
Post reply on HN