Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…
Cybersecurity Incident Involving Consumer Information
191–200 of 551 posts
Re: Cybersecurity Incident Involving Consumer Information
#192"Three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers." https://www.bloomberg.com/news/articles/2017-09-07/three-equ... Edit: Also discussed here https://news.ycombinator.com/item?id=15196309
Re: Cybersecurity Incident Involving Consumer Information
#193Earlier quoted context omitted.
I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…
Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…
The countries that don't have comparable identity theft problems have done so mostly by using an ubiquitous government issued ID that's hard to forge and hard to obtain by someone claiming to be you. In USA there seems to be a strong opposition and a legal barrier for the government to make such an ID.
Not much else can be done - a simple test of a decent identity system is to ask if my spouse, mother or brother would be able to impersonate me - it's clear that nothing that relies on "something you know" can ever be sufficient, it must be "something you are", possibly together with "something you have", i.e., biometrics or a trusted photo ID.
Re: Cybersecurity Incident Involving Consumer Information
#194> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…
I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…
Because this is an issue the government should address seriously.
Re: Cybersecurity Incident Involving Consumer Information
#195Re: Cybersecurity Incident Involving Consumer Information
#196Earlier quoted context omitted.
The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…
Why do we need to number people anyway? People are very consistent with spelling their own names. This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. Think about passwords. A SSN is only nine digits, 0-9. JohnHarrySmith19900101NewYork is far more secure. And doesn't dehumanize the recipient.
Is this true of all people?
> This combined with a birth date and/or a birth city should be enough to uniquely identify anyone.
For common names and large cities, probably not.
> JohnHarrySmith19900101NewYork is far more secure.
No, it's not; SSNs aren't passwords, and shouldn't need to be “secure” in that sense, but names aren't secret and birth dates and locations are easily discoverable (and the combination of all three is frequently publicly announced!), so this would be less secure.
Re: Cybersecurity Incident Involving Consumer Information
#197Time for criminal penalties for the management team. A breach like this will affect thousands of people monetarily and suck time from them they could have used elsewhere. If you've ever dealt with something like this, you know the hours it takes to rectify the damage. The only way corporations will learn to appreciate data security is when management teams suffer criminal penalties.
I don't think it's fair to be throwing any individuals under the bus like that. There's obviously been several failures at multiple levels but the company as a whole will have to face the consequences, not just a few managers it decides to use as scapegoats.
"Three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers."
https://www.bloomberg.com/news/articles/2017-09-07/three-equ...
Re: Cybersecurity Incident Involving Consumer Information
#198Earlier quoted context omitted.
I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…
> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs. Nope. Ain't gonna happen. Financial crime pays, big time! No one goes to Jail. They usually have an investigation followed by a hearing in Congress (if it is "BIG" enough), then come back and pay a fine. Media will report the fine as "MILLIONS OF $" b…
Re: Cybersecurity Incident Involving Consumer Information
#199> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…
Requiring better proof of identity would create friction to consumer credit transactions.
But the change won't happen by itself unless a shift of liability away from the users makes it so that every company doing anything on credit sees that it obviously makes business sense for them to implement the extra friction (and suffer from it) because otherwise they are paying out money to fraudsters instead of trying to collect that from the impersonated people.
Re: Cybersecurity Incident Involving Consumer Information
#200I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…