Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

171–180 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#171
post #24

Earlier quoted context omitted.

I don't understand this. Equifax claims they just leaked my SSN, Drivers License, and other pertinent data to everybody. How would they possibly confirm that I am the one lifting the 'freeze'?

When you get your account frozen they provide a PIN to unlock.

And what happens if I call to unfreeze but have lost the PIN? Can I never get a loan again for the rest of my life? Or is there some way around the PIN - perhaps only requiring the already leaked information?

Re: Cybersecurity Incident Involving Consumer Information

#172
post #91
post #69

Earlier quoted context omitted.

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…

> This is not proof of identity. What is it then? I've seen it used as a quasi-password by car hire companies to access driving license history.

>What is it then?

It is the username you are issued by the government. It is solely used to identify you.

Re: Cybersecurity Incident Involving Consumer Information

#173

Oh nice. A company that does nothing but collect personal information. I’m already in their identity protection program, so I'm a little nonplussed at this.

Are you extremely surprised at this, or not at all? Just from context, I can't quite decide which it is.

I'm not at all surprised, but I am disappointed (to say the least).

Re: Cybersecurity Incident Involving Consumer Information

#174
post #164
post #150

Earlier quoted context omitted.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

Change the way checks are issued/redeemed. Right now the customer is on the hook for 7 years because a check isn't cleared until it goes back to the bank that issued the check . The customer thinks by seeing the money in the account the check was good and can clear a sale. The reality is the bank can take that money back if it is later determined to be false/fake.

Paper checks are going away. Some of the online banks don't even support them. ACH allows only 60 days to claw back the money(disputes) and with same day clearing requirement we can get rid of 2 day holds.

Re: Cybersecurity Incident Involving Consumer Information

#175
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

And not only do I have to give them personal information to check, I have to use google's sign-reading I'm-not-a-robot captcha - feeding a little of my intellectual capability to their self-driving car companies.

They keep taking...

Re: Cybersecurity Incident Involving Consumer Information

#176

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Why not just shift the presumption of liability (absent verification) to the financial institution instead of the consumer? Loan issuers can hire skilled professionals to do credit verification, so why should consumers bear the risk for their lack of due diligence?

"just"

Consumers would love this. Financial institutions would not. Guess who wins this battle?

Re: Cybersecurity Incident Involving Consumer Information

#177
post #66
post #53

Earlier quoted context omitted.

Why do you think Equifax (or Home Depot, or Target) is any less of a victim here?

I leave my home with a house sitter. The house sitter throws a kegger, and his guests cause six figures worth of property damage, including stealing the house sitter's laptop. Who are all the criminal parties here?

So you're saying that companies that get hacked are "asking for it", or are complicit in the criminal activity? That's an incredibly broad stretch.

Re: Cybersecurity Incident Involving Consumer Information

#178
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Clearly, both the bank and the individual are victims of the crime.

Generally speaking, the impact to the customer is usually greater, as bank business model aren't dependent on every loan being repaid. Consumers stand to lose money directly and lose the opportunity to access capital.

The credit agency or anyone else who has a breach is usually a negligent third party.

Re: Cybersecurity Incident Involving Consumer Information

#179
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

I also noted that it asked for the last 6 digits of your social. Could be they need more digits to avoid duplicates, but I've never heard anyone ask for 6 digits. Usually it's just the 4. Honestly, they should have used a subdomain off of Equifax.com.

The bad thing about that is the first 3 digits are the location digits, so someone that has the last 6 digits can easily guess your full SSN if they know where you were born (or where you lived when you got your SSN).

https://en.wikipedia.org/wiki/List_of_Social_Security_Area_N...

Re: Cybersecurity Incident Involving Consumer Information

#180
post #47

Earlier quoted context omitted.

Accountable for what? That they're a target for hackers, who managed to break into their network? How is that careless? There's no such thing as perfect security.

This case seems a little different in that it's pretty difficult to not have your personal information in their system. You roll in to Target or Home Depot, you decide to pay with a check, card or cash. You decide to give them your information or not. You decide if you want to go back after they mismanage your information. Can you opt out of Equifax's business and still get credit or loans? Can you even opt out at al…

You're assuming mismanagement...but there's simply no way to guarantee perfect computer security.
Post reply on HN