Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

231–240 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#231

Earlier quoted context omitted.

We don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If yo…

Not really conjecture: > The company has found no evidence of unauthorized activity on Equifax’s core consumer or commercial credit reporting databases. Since core business was unaffected (nobody hacked the mainframe), I guarantee you some crappy product they acquired got compromised. And like it or not, you do give them permission to collect your personal data every time you authorize a creditor, utility or employer…

It could also be related to how they sell things. Given how commonly they redistribute this data I wouldn't be surprised if it turned out to be something like a customer portal where they can say it wasn't core because the attacker couldn't have altered data, etc.

Re: Cybersecurity Incident Involving Consumer Information

#232
post #207
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

By enrolling in the free "Identity Theft Protection" you waive your right to "PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, OR OTHER REPRESENTATIVE ACTION" https://trustedidpremier.com/static/terms It is a scam to get people to sign away their rights to sue the bastards.

Can anyone with a legal background or have connections to news outlets validate this? I read through the terms and this really does seem to be the case. However, I am certainly not in a position to decide this. It would alleviate my concerns if a trusted source could publicly report on how the impacted (pretty much everyone in the US) should respond to leak.

Re: Cybersecurity Incident Involving Consumer Information

#233
post #154
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Precisely. In no way was Alice's identity stolen - that's tautologically impossible. Rather, the bank was defrauded by the criminal - Alice is of not a party to whether or not the bank recovers from its own loss. Alice's ownership is entirely unaffected, though the bank's internal processes might not reflect that - again, their problem, not Alice's. Further - this rat race, where I have to give ever more intimate det…

I've worked a bit in the industry and around the industry, the worrying thing for me is that it doesn't seem to be working for anyone apart from equifax/experian/call credit.

I have separately worked with one of those companies with a client and their IT staff were utterly incompetent (I won't say which). Loads of different sites, lots of little fiefdoms, utterly inconsistent security policies on each site, blaming everyone but themselves because only half their sites could access a video on a major commercial video provider (not-youtube). We ended up having to host it on AWS cloudfront as none of them had blocked it yet. Their sharepoint could only host a 50mb file, which made their CEO look like a blockhead in the 20 min high def video.

Utterly incapable of hosting a simple video file so all their staff could access it in 2010.

I've also worked with a company one of those companies acquired for $100 million+, holding millions of people's personal details in the UK, with some very sensitive data. Some of the worst IT engineering I have ever seen, a bunch of tools written by the worst out-sourced IT teams I have ever seen (if you've ever worked with C#, these idiots made a project per .cs file. Yes, PER CS FILE. They also wrote the worst SQL I have ever seen, all of the stored procedures seemed to be duplicated but the duplicates had op_ before them. I eventually realised the op_ stood for optimized! They were still terrible and half the program used one set of SQL, the other half the optimised. Whenever I re-wrote one of these 'optimised' queries, I usually knocked it from seconds to milliseconds. Outsourcers in the naughties really did suck that bad, young 'uns).

We've given up huge amounts of privacy, but the scores are utter bullshit and the 2008 crash show what a load of nonsense they are.

A friend even told me at uni he'd got a £1000 loan out to get a good credit rating. You just put the money in an account, pay the capital off every month, lose a little bit of interest and in 2 years you have a shiny credit rating even though it means zilch.

equifax/experian/call credit basically get given all our personal spending habits for free, sell it on to everyone else for crazy money, don't add anything to the economy and as far as i can tell, are a huge security hole.

EDIT: Another anecdote on how incompetent these people are, a couple of years ago someone used my details to scam a few free phones. I got alerted to it when I started receiving insurance contracts for those phones in the post. The phone companies sorted it pronto, almost immediately admitting they'd been scammed, but I wanted to make sure my credit rating hadn't been trashed. In the UK these agencies must provide you with a credit report for a nominal fee so you can check for incorrect details, so I applied to the big 3.

One of them accused me of trying to hack their system because I'd forgotten a security question, eventually told me to fuck off after passing through various layers, then sent me a letter saying they'd detected a hacker trying to access my details. No, you idiots, that was me. Still never got my report from them.

Yes, they still use security questions.

Re: Cybersecurity Incident Involving Consumer Information

#234
post #154
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Precisely. In no way was Alice's identity stolen - that's tautologically impossible. Rather, the bank was defrauded by the criminal - Alice is of not a party to whether or not the bank recovers from its own loss. Alice's ownership is entirely unaffected, though the bank's internal processes might not reflect that - again, their problem, not Alice's. Further - this rat race, where I have to give ever more intimate det…

> In no way was Alice's identity stolen - that's tautologically impossible.

I see this as you being too strict with your definition of "identity".

We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc.

"Stolen identity" in this sense means Alice's attributes (the ones which Big Bank uses to identify a person) have been compromised by a 3rd party. It's not that all of Alice's identity has been compromised -- only a subset of her identity. Sadly that subset almost entirely consists of "something you know" (which the internet usually also knows) rather than "something you have" (like a government-issued ID) or "something you are" (biological traits).

I totally agree about the rat race. I think the credit bureaus are complicit in keeping the burden of credit identity low and the availability of credit reports high in the US, both of which lead to perverse incentives for {credit bureaus, consumers, creditors, governments, etc}. But they aren't alone. Credit card systems {VISA, Mastercard, AMEX, Discover, etc} and credit card merchants have done the same, causing the US to fall far behind other developed countries in consumer security.

Additionally, I've heard horror stories about the effort required for consumers to "prove" to credit bureaus that their identity was stolen. It sounds a lot like the insurance company's policies in The Rainmaker.

Re: Cybersecurity Incident Involving Consumer Information

#236
Points to the wise, always keep your credit FROZEN. All three of the big credit firms make it simple to do and it has been easy to unlock when I wanted to do so. if I know I am going to want to use my credit for a new account I identify which one the bank/merchant/etc will use and unlock it for 48 hours.

Re: Cybersecurity Incident Involving Consumer Information

#237
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…

This is a great description of what is going on with "identity theft". I don't usually like changing the name of something to try to push an agenda, but calling "identity theft" "bank slander" would be good idea.

Re: Cybersecurity Incident Involving Consumer Information

#238
post #207
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

By enrolling in the free "Identity Theft Protection" you waive your right to "PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, OR OTHER REPRESENTATIVE ACTION" https://trustedidpremier.com/static/terms It is a scam to get people to sign away their rights to sue the bastards.

IANAL, but I'm not sure that you are correct. The agreement refers to claims "arising from or relating to the subject matter of this Agreement or the Products", and the title of the agreement is "TrustedID Premier Terms of Use".

Doesn't that mean you're waiving your right to sue TrustedID, Inc. in a class action for grievances related to the TrustedID monitoring product, not your right to sue Equifax for the data breach?

Re: Cybersecurity Incident Involving Consumer Information

#239
There should be a way to freeze all 3 (and/or all significant) from a single web site, and it should be free. It's mind blowing to me that this isn't codified into law yet.

Actually, if someone did this (well) as a service I would probably even pay a small amount of money for it. Startup idea?

Re: Cybersecurity Incident Involving Consumer Information

#240
post #164

Earlier quoted context omitted.

Change the way checks are issued/redeemed. Right now the customer is on the hook for 7 years because a check isn't cleared until it goes back to the bank that issued the check . The customer thinks by seeing the money in the account the check was good and can clear a sale. The reality is the bank can take that money back if it is later determined to be false/fake.

> customer is on the hook for 7 years 7 years? Are you sure it's not something like 7 days?

It takes 7 years for a bankruptcy to clear your credit record in the USA.
Post reply on HN