Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

261–270 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#261
So, can anyone tell me, why are there three credit agencies? Why not one, or thirty? Could I start a credit agency, just by judging that certain people are level 9000 reliable, and others are just level 100 reliable? I swear it's not slander, everyone I refer to is reliable, it's just that some of them have demonstrated exceptional reliability.

Re: Cybersecurity Incident Involving Consumer Information

#262
This entire thing is a joke and will continue to be a joke until we get laws that hold executives personally criminally responsible for breaches. Together with automatic forfeiture of personal assets. As long as there's no personal motivation from people who make hundreds of millions of dollars by sitting on a top of the pyramid nothing is going to change.

Re: Cybersecurity Incident Involving Consumer Information

#263
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Clearly, both the bank and the individual are victims of the crime. Generally speaking, the impact to the customer is usually greater, as bank business model aren't dependent on every loan being repaid. Consumers stand to lose money directly and lose the opportunity to access capital. The credit agency or anyone else who has a breach is usually a negligent third party.

Not sure how the individual is victimised by the fraudster here. If the bank had a 100% success rate at detecting fraud with no false positives and no false negatives, then the individual wouldn't need to know and likely would never find out about the impersonation attempt.

The individual is victimised by the bank and the credit reporting agencies by their spread of misinformation.

Re: Cybersecurity Incident Involving Consumer Information

#264

Earlier quoted context omitted.

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs.

No. With jail. And go bankrupt.

Re: Cybersecurity Incident Involving Consumer Information

#265
post #120

Earlier quoted context omitted.

I got the same page, but then I tried putting in a fake name and got: > Thank You > Based on the information provided, we believe that your personal information was not impacted by this incident. So if you just get the enrollment date, I think that means you’re affected.

From the r/personalfinance thread, the site kicks back 3 different JSON status messages: "message-deferred": "Thank You -- Your enrollment date for TrustedID Premier is: xxxxxx Please be sure to mark your calendar as you will not receive additional reminders. On or after your enrollment date, please return to faq.trustedidpremier.com and click the link to continue through the enrollment process." "message-success": "…

So... later date means they don't know yet? Or you have been impacted and you're only eligible to enroll later?

Re: Cybersecurity Incident Involving Consumer Information

#266
post #36
post #4

Earlier quoted context omitted.

It sounds like ssn is not fit for purpose. If the gov is going to issue a 'secret number ' why not a 2fa device?

The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…

The honor system didn't work. When they put in the SSN requirement, the number of children reported on tax returns dropped by 10% (from 77 million to 70 million): http://articles.latimes.com/1989-12-11/local/me-33_1_exempti...

Re: Cybersecurity Incident Involving Consumer Information

#267
post #206
post #37

Earlier quoted context omitted.

Equifax can handle its internal management and operations however it wants. Externally, though, I want Equifax to have to pay a fine for every individual whose information was compromised. Identity theft can easily cause five figures worth of damage, so $10k per individual would be fair. Maybe as a warning shot we could lower this to... $1k? $100? That's the only way to properly align incentives so companies will pro…

$1k, $100, that's far too low in my opinion even for a warning shot. As someone who has had their info leaked by two universities before, both of whom subsequently paid for multiple years of credit/fraud protection, the sheer pain and stress of having random credit cards frozen and need to be replaced is worth far more than that dollar amount of my time. This is potentially messing with people's livelihoods with long…

$1k would mean a $146 billion fine in this case. Hardly a "tiny figure".

Re: Cybersecurity Incident Involving Consumer Information

#268
post #170
post #40

Time for criminal penalties for the management team. A breach like this will affect thousands of people monetarily and suck time from them they could have used elsewhere. If you've ever dealt with something like this, you know the hours it takes to rectify the damage. The only way corporations will learn to appreciate data security is when management teams suffer criminal penalties.

I don't think it's fair to be throwing any individuals under the bus like that. There's obviously been several failures at multiple levels but the company as a whole will have to face the consequences, not just a few managers it decides to use as scapegoats.

> I don't think it's fair to be throwing any individuals under the bus like that. There's obviously been several failures at multiple levels but the company as a whole will have to face the consequences, not just a few managers it decides to use as scapegoats.

Why not?

Re: Cybersecurity Incident Involving Consumer Information

#269

Earlier quoted context omitted.

You get a unique long pin code when you freeze the account. You need that to unfreeze it. There is some "recovery" procedure, I think you need a notary or something

And that unique long pin definitely isn't stored in plaintext in the next column over in their database, right?

"don't worry, your 12 digit pin is securely encrypted with md5"

/s

Re: Cybersecurity Incident Involving Consumer Information

#270
post #37

Earlier quoted context omitted.

Equifax can handle its internal management and operations however it wants. Externally, though, I want Equifax to have to pay a fine for every individual whose information was compromised. Identity theft can easily cause five figures worth of damage, so $10k per individual would be fair. Maybe as a warning shot we could lower this to... $1k? $100? That's the only way to properly align incentives so companies will pro…

I would not doubt a class action lawsuit results from this, and I'd be very surprised if Elizabeth Warren didn't pursue congressional action against them (although not officers of the company unfortunately).

And? Who cares what a fake Indian says from a floor of the Senate?
Post reply on HN