Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

241–250 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#241
post #150

Earlier quoted context omitted.

This is very clearly what's going on. Fraud is uncommon enough and the cost of fraud to the banks is smaller than the cost of reducing the velocity of money and loan-making, so the problem will never get fixed so long as it depends on the banks to initiate the fix.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those authorizations to each other. Individuals who need more flexibility could opt out or do something more complicated, at the cost of some risk.

There's some cost to this, but I still suspect quite a few people would accept it.

Re: Cybersecurity Incident Involving Consumer Information

#242
post #36

Earlier quoted context omitted.

The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…

Why do we need to number people anyway? People are very consistent with spelling their own names. This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. Think about passwords. A SSN is only nine digits, 0-9. JohnHarrySmith19900101NewYork is far more secure. And doesn't dehumanize the recipient.

This is definitely not reliable in large cities, and it would have privacy concerns not to mention failing to handle people who don't follow the same naming conventions you do or who don't have day-level precision on their birth date.

See http://www.kalzumeus.com/2010/06/17/falsehoods-programmers-b... and especially http://latanyasweeney.org/work/identifiability.html

Numbers have the nice advantage of not assuming structure, character set, etc. and allow changes for edge cases such as someone escaping an abusive spouse — see the full list of reasons at https://faq.ssa.gov/link/portal/34011/34019/article/3789/can...

Re: Cybersecurity Incident Involving Consumer Information

#243
post #154

Earlier quoted context omitted.

Precisely. In no way was Alice's identity stolen - that's tautologically impossible. Rather, the bank was defrauded by the criminal - Alice is of not a party to whether or not the bank recovers from its own loss. Alice's ownership is entirely unaffected, though the bank's internal processes might not reflect that - again, their problem, not Alice's. Further - this rat race, where I have to give ever more intimate det…

I've worked a bit in the industry and around the industry, the worrying thing for me is that it doesn't seem to be working for anyone apart from equifax/experian/call credit. I have separately worked with one of those companies with a client and their IT staff were utterly incompetent (I won't say which). Loads of different sites, lots of little fiefdoms, utterly inconsistent security policies on each site, blaming e…

You just put the money in an account, pay the capital off every month, lose a little bit of interest and in 2 years you have a shiny credit rating even though it means zilch.

I don’t really get that - doesn’t it mean that the person who took a loan is relatively responsible and was able to pay their loan back on time?

Any system can be gamed, but I don’t get the impression that credit agencies are attempting to eliminate all risk - after all, it’s obviously possible that someone who has had perfect credit for years might simply run away with your cash! But the system doesn’t have to be perfect, or detect all outliers, to have value.

It seems intuitively obvious that lending to someone who is frequently late with credit repayments is riskier than lending to one who isn’t, and this is the mechanism by which that information is shared.

Re: Cybersecurity Incident Involving Consumer Information

#244
They got hacked years ago. I know this for sure because I'd used a unique email address to sign up on their website: equifax@.com

No one else had that email address. Guess what, I started getting phishing emails to that exact address.

Tried letting them know, but it went nowhere.

Re: Cybersecurity Incident Involving Consumer Information

#245

Earlier quoted context omitted.

What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…

This is a great description of what is going on with "identity theft". I don't usually like changing the name of something to try to push an agenda, but calling "identity theft" "bank slander" would be good idea.

So presumably a class action law suit against the reporters for slander? Might depend on specifics of the law... Maybe it's time for a better credit reporting agency startup.

Re: Cybersecurity Incident Involving Consumer Information

#246
post #216

Earlier quoted context omitted.

It is a protection racket that shifts the risks and costs from the financial system to consumers.

Same with chip and pin here in the UK

I have heard of no cases where liability has been shifted in that way.

Re: Cybersecurity Incident Involving Consumer Information

#247
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

This argument is akin to splitting hairs. The fraudster who applied for the loan against BigBank was at fault. The BigBank accepted the Fraud and reported it to the credit agency. The Credit Bureau reports/includes the data provided by BigBank; it's what they do.

If there is a dispute between what BigBank says and what Alice says, it's not necessarily so easy to resolve, and that's the position the Credit Bureau has to deal with.

To absolve the fraudster of the primary fault is ridiculous. That said, this is the problem with difficulties in identity verification, we all want privacy and security at the same time. While they are not mutually exclusive, having both is much more complicated than one or the other.

Re: Cybersecurity Incident Involving Consumer Information

#248
These fuckers should literally be put out of business. They have one job, and they fail at it time and time again. They can't be trusted with our data. They need to be shut down. Does anyone know how to start a ballot measure in California to create a Proposition to stop using Equifax in California?

Re: Cybersecurity Incident Involving Consumer Information

#249
post #55

Earlier quoted context omitted.

And then I'll get six months of free credit monitoring from Equifax? Oh boy!!1! More seriously, this is a breach big enough that Equifax should honestly no longer exist as a company. So call it $100/incident, and I'm happy. Other agencies would still exist, and, although they're just as terrible, it might get them to kick their asses into high gear to fix their security.

The NYT story states that they are already offering this to affected consumers: https://www.equifaxsecurity2017.com/potential-impact/ .

The content of the landing page (since it appears broken, here's the content from Reader View):

Equifax Announces Cybersecurity Incident Involving Consumer Information

[Equifax CEO statement] https://youtu.be/bh1gzJFVFLc

No Evidence of Unauthorized Access to Core Consumer or Commercial Credit Reporting Databases

Company to Offer Free Identity Theft Protection and Credit File Monitoring to All U.S. Consumers

September 7, 2017 — Equifax Inc. (NYSE: EFX) today announced a cybersecurity incident potentially impacting approximately 143 million U.S. consumers. Criminals exploited a U.S. website application vulnerability to gain access to certain files. Based on the company’s investigation, the unauthorized access occurred from mid-May through July 2017. The company has found no evidence of unauthorized activity on Equifax’s core consumer or commercial credit reporting databases.

The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers. In addition, credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed. As part of its investigation of this application vulnerability, Equifax also identified unauthorized access to limited personal information for certain UK and Canadian residents. Equifax will work with UK and Canadian regulators to determine appropriate next steps. The company has found no evidence that personal information of consumers in any other country has been impacted.

Read More

Re: Cybersecurity Incident Involving Consumer Information

#250
This is why I'm not secretive about my SSN. My neighbor, roommate or a random passerby isn't the attack vector, it is the trusted institution.

I'm not going to post it here, but I wouldn't even mind saying it over the phone while standing in line somewhere. Its just not the real attack vector.

Result here shows that whispering it and writing it down on posted notes for a bank teller have zero bearing on your identity security.

Post reply on HN