Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

161–170 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#161

Earlier quoted context omitted.

This thing called "Identity Theft" does cause damage, but it's important to remember that if fraudsters trick a bank into thinking they are you, it is the bank's fault for failing to properly verify it was actually you. Doing so would cost them more money and it is much easier to do cursory checks instead. No doubt fraudsters impersonating you is a hassle and you must spend some time and money dealing with it if you…

But you still pay the fees from the banks failings, so it really does hurt everyone even when the bank eats it.

It hurts everyone foolish enough to still do business with the bank after they jack up their fees to pay for it. Or in jurisdictions where a small number of banks are given a monopoly, or competition is otherwise discouraged, it hurts everyone.

Re: Cybersecurity Incident Involving Consumer Information

#162
From the article: "No Evidence of Unauthorized Access to Core Consumer or Commercial Credit Reporting Databases." Later on they say "The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver's license numbers."

I am having a difficult time reconciling those two sentences.

Re: Cybersecurity Incident Involving Consumer Information

#163
post #99

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

At this stage, if you have to pay the company that leaks your own data to prevent it from harming you, it starts to sound like protection racket.

It is a protection racket that shifts the risks and costs from the financial system to consumers.

Re: Cybersecurity Incident Involving Consumer Information

#164
post #150

Earlier quoted context omitted.

This is very clearly what's going on. Fraud is uncommon enough and the cost of fraud to the banks is smaller than the cost of reducing the velocity of money and loan-making, so the problem will never get fixed so long as it depends on the banks to initiate the fix.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

Change the way checks are issued/redeemed. Right now the customer is on the hook for 7 years because a check isn't cleared until it goes back to the bank that issued the check . The customer thinks by seeing the money in the account the check was good and can clear a sale. The reality is the bank can take that money back if it is later determined to be false/fake.

Re: Cybersecurity Incident Involving Consumer Information

#165
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

My brother's university student ID number was his SSN. It was a top-10 public university. That's how stupid we've collectively been about it.

Re: Cybersecurity Incident Involving Consumer Information

#166
post #147
post #120

Earlier quoted context omitted.

I got the same page, but then I tried putting in a fake name and got: > Thank You > Based on the information provided, we believe that your personal information was not impacted by this incident. So if you just get the enrollment date, I think that means you’re affected.

You can proceed with the enrollment anyway, even if you receive that message, with any set of six digits and any set of characters for the last name and receive a message indicating that you're enrolled. I watched the video of the CEO describing what Equifax was doing in response to the incident and he does not specifically name "equifaxsecurity2017.com" or "trustedidpremier.com" as the sites they've set up, only tha…

To that end: if you're an HN user with the last name "HHHHHH" and with a Social Security number ending in 000000, don't worry about enrolling. I very helpfully took care of it for you!

Re: Cybersecurity Incident Involving Consumer Information

#167

Earlier quoted context omitted.

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> So, if I hack TU, all I need to do is get the data of the people who asked for a credit freeze.

Sure, but TU already has all the above information anyways.

Re: Cybersecurity Incident Involving Consumer Information

#168

Earlier quoted context omitted.

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

We don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If yo…

Not really conjecture:

> The company has found no evidence of unauthorized activity on Equifax’s core consumer or commercial credit reporting databases.

Since core business was unaffected (nobody hacked the mainframe), I guarantee you some crappy product they acquired got compromised.

And like it or not, you do give them permission to collect your personal data every time you authorize a creditor, utility or employer to run a credit check. Never sign up for utilities, loans, credit cards or get a job and then you'd have a case for privacy.

Re: Cybersecurity Incident Involving Consumer Information

#169
"Three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers."

https://www.bloomberg.com/news/articles/2017-09-07/three-equ...

Edit: Also discussed here https://news.ycombinator.com/item?id=15196309

Re: Cybersecurity Incident Involving Consumer Information

#170
post #40

Time for criminal penalties for the management team. A breach like this will affect thousands of people monetarily and suck time from them they could have used elsewhere. If you've ever dealt with something like this, you know the hours it takes to rectify the damage. The only way corporations will learn to appreciate data security is when management teams suffer criminal penalties.

I don't think it's fair to be throwing any individuals under the bus like that. There's obviously been several failures at multiple levels but the company as a whole will have to face the consequences, not just a few managers it decides to use as scapegoats.
Post reply on HN