Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

211–220 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#211

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

This is actually a major inconvenience. You won't be able to apply for credit cards or get a loan to buy a car if you have a credit freeze. You have to unfreeze and re-freeze each time you apply for a credit card, and this costs about $30.

How often to you apply for credit?

It is, in any case, far less of an inconvenience than not paying the protection racket, having someone impersonate you, and having the credit oligopoly lie about you because of it, leaving you to somehow clean up their mess.

Re: Cybersecurity Incident Involving Consumer Information

#212

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Question for you: My card comes with Identity theft protection [1]. Do you think that's a good alternative to freezing credit completely? [1] https://www.discover.com/credit-cards/member-benefits/securi...

[deleted]

Re: Cybersecurity Incident Involving Consumer Information

#213

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

This is actually a major inconvenience. You won't be able to apply for credit cards or get a loan to buy a car if you have a credit freeze. You have to unfreeze and re-freeze each time you apply for a credit card, and this costs about $30.

It depends on your situation. I've done this for the last 3 years, and have only had to lift the freeze a 2 times, both times actually for job offers (it's pretty routine for companies to run background checks on new hires, which includes a credit history check). It does cost ~$30, but can be done online, and takes little time. You can also reduce the cost by asking whoever wants to legitimately check on your credit history, which reporting agency they will be checking with. Then you only need to lift the freeze for that agency, and for that entity asking for a report.

If there isn't some handshake/ack mechanism like this, I'm not sure how you cut back on fraudulent activity. I can see the case for making the credit agencies eat this cost and provide these services for free. That would probably require an act of congress...

Edit: You could also ask a potential employer to eat the cost of unfreezing to check your credit history, or ask them not to do the check at all (especially if it's not really relevant to your job). Either request seems reasonable to me, although I haven't tried that, I'm betting at least most employers would pay for the unfreeze.

Re: Cybersecurity Incident Involving Consumer Information

#214
post #9

Is anyone being punished for all of the massive security breaches which appear to be happening on a nearly daily basis?

I'm not a lawyer, and I don't know if what they've done violated the FCRA (Fair Credit Reporting Act). That said, doing a bit of research, if they've violated the FCRA knowingly, they're liable for actual damages, plus no more than $1,000 per incident, but also no less than $100 per incident. If it's just inadvertent negligence, then they're only liable for actual damages.

So, assuming each person whose info was compromised is a separate incident, willfully negligent violation could result in up to a company-shattering $143B fine, but no less than $14.3B on the low end. I imagine that that even the lower figure would be hard for them to absorb as well.

I have to imagine that class action lawyers all over the country are licking their lips, if there's an opening via FCRA. I'm not sure what the FCRA says about PII data security practices, though - it might just be having processes in place and the like.

Re: Cybersecurity Incident Involving Consumer Information

#215
post #127
post #107

Hm, I tried using their tool to see if I've been impacted: https://www.equifaxsecurity2017.com/potential-impact/ Which says it would tell me if I'm likely impacted, but instead it just gives a date where I can enroll in some free product, but no info on whether I'm likely compromised. Anyone have a workaround? This is important to anyone that wants to identify if they've been "pwned."

This site seems shady as hell. As well is the trustedidpartner.com which has no homepage that it refers you to. Seems like a phishing scam.

It is linked from the banner up top of https://www.equifax.com/personal/

"Equifax Cybersecurity Incident: To learn more about the cybersecurity incident, including whether your personal information was potentially impacted, or to sign up for complimentary identity theft protection and credit file monitoring, click here"

and that "click here" goes to http://www.equifaxsecurity2017.com/

So it'd seem legit, if rather silly to have its own domain.

Re: Cybersecurity Incident Involving Consumer Information

#216
post #99

Earlier quoted context omitted.

At this stage, if you have to pay the company that leaks your own data to prevent it from harming you, it starts to sound like protection racket.

It is a protection racket that shifts the risks and costs from the financial system to consumers.

Same with chip and pin here in the UK

Re: Cybersecurity Incident Involving Consumer Information

#217
post #198

Earlier quoted context omitted.

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs. Nope. Ain't gonna happen. Financial crime pays, big time! No one goes to Jail. They usually have an investigation followed by a hearing in Congress (if it is "BIG" enough), then come back and pay a fine. Media will report the fine as "MILLIONS OF $" b…

If they did that because of this, the SEC will likely nail them for it.

Of the three letter agencies, the IRS and the SEC are particularly ruthless. They can only enforce what Congress will allow, unfortunately, so that leads to bigger fish not being fried up.

Re: Cybersecurity Incident Involving Consumer Information

#218
post #120
post #107

Hm, I tried using their tool to see if I've been impacted: https://www.equifaxsecurity2017.com/potential-impact/ Which says it would tell me if I'm likely impacted, but instead it just gives a date where I can enroll in some free product, but no info on whether I'm likely compromised. Anyone have a workaround? This is important to anyone that wants to identify if they've been "pwned."

I got the same page, but then I tried putting in a fake name and got: > Thank You > Based on the information provided, we believe that your personal information was not impacted by this incident. So if you just get the enrollment date, I think that means you’re affected.

From the r/personalfinance thread, the site kicks back 3 different JSON status messages:

  "message-deferred": "Thank You -- Your enrollment date for TrustedID Premier is: xxxxxx Please be sure to mark your calendar as you will not receive additional reminders. On or after your enrollment date, please return to faq.trustedidpremier.com and click the link to continue through the enrollment process."

  "message-success": "Thank You -- Based on the information provided, we believe that your personal information may have been impacted by this incident. Click the button below to continue your enrollment in TrustedID Premier."

  "message-not-impacted": "Thank You -- Based on the information provided, we believe that your personal information was not impacted by this incident. Click the button below to continue your enrollment in TrustedID Premier"

Re: Cybersecurity Incident Involving Consumer Information

#219
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Clearly, both the bank and the individual are victims of the crime. Generally speaking, the impact to the customer is usually greater, as bank business model aren't dependent on every loan being repaid. Consumers stand to lose money directly and lose the opportunity to access capital. The credit agency or anyone else who has a breach is usually a negligent third party.

They are victims of very different things though.

The bank is a victim of fraud.

The individual is a victim of impersonation by the borrower, and slander by the bank and credit agencies.

Re: Cybersecurity Incident Involving Consumer Information

#220
post #174
post #164

Earlier quoted context omitted.

Change the way checks are issued/redeemed. Right now the customer is on the hook for 7 years because a check isn't cleared until it goes back to the bank that issued the check . The customer thinks by seeing the money in the account the check was good and can clear a sale. The reality is the bank can take that money back if it is later determined to be false/fake.

Paper checks are going away. Some of the online banks don't even support them. ACH allows only 60 days to claw back the money(disputes) and with same day clearing requirement we can get rid of 2 day holds.

What are they being replaced with? Yeah, as a young renter I went years without using a check. When buying a home last year I had various inspectors during the process. After buying, I've had electricians, plumbers, contractors, locksmiths, and other consultants. I think one gave me a bill and accepted credit card. The rest preferred checks (to be fair, I didn't seek other forms).

I've tried all sorts of p2p methods over the years. All of the banks are too confusing, obscure, or too limited (i.e. only within their bank). Paypal and credit cards charge a not-insignificant fee. Venmo or Square Cash work fine if your group of friends accept them--but more than half the time, they don't for me.

I often do ACH transfers between my own accounts, but the first time I set it up a cringe a little bit and cross my fingers. It sucks waiting the 2 or 3 days waiting to see something. I can't see small businesses accepting ACH as payment because they want something in hand. If we had the setup I've heard about in Britain or Europe, I can see checks going away, but with as much churn as I've seen in this space in the 20 years since Paypal, nothing seems to stick.

Post reply on HN