Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

301–310 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#301
post #55

Earlier quoted context omitted.

And then I'll get six months of free credit monitoring from Equifax? Oh boy!!1! More seriously, this is a breach big enough that Equifax should honestly no longer exist as a company. So call it $100/incident, and I'm happy. Other agencies would still exist, and, although they're just as terrible, it might get them to kick their asses into high gear to fix their security.

The NYT story states that they are already offering this to affected consumers: https://www.equifaxsecurity2017.com/potential-impact/ .

Even better, they ask for your last name and the last six digits of your SSN to even check your potential impact. The problem is that the first three digits of your SSN are derived from your state of birth, so the last six give up basically the entire thing. http://www.ssofficelocation.com/social-security-number-prefi...

This whole system is so fucked.

Re: Cybersecurity Incident Involving Consumer Information

#302
post #150

Earlier quoted context omitted.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

My information was used to open a fraudulent mortgage loan, then when I asked my bank to not allow opening credit lines or transfers online was told "we can't do that!"

Re: Cybersecurity Incident Involving Consumer Information

#303

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

My hope is that with this breach, someone will finally be able to hit Congress over the head with a smart stick and make them realize this.

Good lucky. The people responsible for this will likely go on to work in the government.

Re: Cybersecurity Incident Involving Consumer Information

#304
post #207
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

By enrolling in the free "Identity Theft Protection" you waive your right to "PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, OR OTHER REPRESENTATIVE ACTION" https://trustedidpremier.com/static/terms It is a scam to get people to sign away their rights to sue the bastards.

Aha, that explains why the site works so hard to gather your info and then suddenly loses interest in doing anything much else!

Shit I hope I don't miss out on like $3.37 of class-action BOUNTY!

Re: Cybersecurity Incident Involving Consumer Information

#305

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Question for you: My card comes with Identity theft protection [1]. Do you think that's a good alternative to freezing credit completely? [1] https://www.discover.com/credit-cards/member-benefits/securi...

That's a bad idea I think. You are giving your card company proxy rights, and more data about yourself then they should have.

Re: Cybersecurity Incident Involving Consumer Information

#306
post #292
post #132

Earlier quoted context omitted.

Putting aside the whole "punishing the victim" argument, the problem is that it's excruciatingly hard to draw a line between "being careless" and "you did everything right but it still wasn't enough", and thus it's really hard to punish someone for cybersecurity mistakes. I work in cybersec consulting, and it's certainly true that a large number of companies are simply not investing enough money/time/effort into cybe…

>and thus it's really hard to punish someone for cybersecurity mistakes No. If you take it upon yourself to hold this information, you are accepting the responsibility for its disclosure. If you are not willing to accept penalty for this happening despite your best efforts, you should not be doing it.

So, what should we do? Should we just fire/jail everyone who has ever worked for a company that was breached? You realize that would be literally everyone, in pretty much every company ever, right? There's a saying in the cybersec world: "there are two types of companies: those who know they've been hacked, and those who don't realize it yet".

Cybersecurity is a field where there's already not enough good talent. And even the very best talent is still going to not be good enough from time to time.

It is simply completely naive and unrealistic to expect a company to be 100% hack-proof, and if you start punishing people for that, then you're just not going to have anyone taking the job at all, and you're going to have even less security.

Re: Cybersecurity Incident Involving Consumer Information

#307
post #154

Earlier quoted context omitted.

Precisely. In no way was Alice's identity stolen - that's tautologically impossible. Rather, the bank was defrauded by the criminal - Alice is of not a party to whether or not the bank recovers from its own loss. Alice's ownership is entirely unaffected, though the bank's internal processes might not reflect that - again, their problem, not Alice's. Further - this rat race, where I have to give ever more intimate det…

> In no way was Alice's identity stolen - that's tautologically impossible. I see this as you being too strict with your definition of "identity". We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. "Stolen identity" in this sense means Alice's attributes (the ones which Big Bank uses to identify a person…

> I see this as you being too strict with your definition of "identity".

> We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc.

Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly be pointing to one body (hence they supposedly identify Alice) while it is claimed at the same time that they can be replicated by a "thief", which necessarily implies that they don't identify Alice, and hence are not an identity, therefore tautological impossibility.

For example, it is claimed that being able to say the DoB of Alice is an attribute that identifies Alice's body. Then, it is also claimed that somebody else saying Alice's DoB supposedly is an act of stealing her identity, and that the set of such people is non-empty. Which means that being able to say Alice's DoB is not actually an identity in the first place, much less one that could be stolen.

Re: Cybersecurity Incident Involving Consumer Information

#308

Earlier quoted context omitted.

You just put the money in an account, pay the capital off every month, lose a little bit of interest and in 2 years you have a shiny credit rating even though it means zilch. I don’t really get that - doesn’t it mean that the person who took a loan is relatively responsible and was able to pay their loan back on time? Any system can be gamed, but I don’t get the impression that credit agencies are attempting to elimi…

For £100 you get a shiny credit rating for no risk. That'll get you a mortgage for £100,000s. In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. I appreciate that it probably benefited a certain type of person, but the new system probably has the same prejudices built in. Now it's all about the ephemeral and easily game-able credit score. Until a few years ago you would get negati…

> I was not a good risk.

Banks are using actuarial science to make loans. You were (possibly) an outlier. That doesn't matter. All that matters is that their risk models work in aggregate. If they're right enough of the time, they profit. It doesn't have to be perfect.

Re: Cybersecurity Incident Involving Consumer Information

#309
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…

Wow, I learned a ton from this comment. I would have never come up with this on my own.

Re: Cybersecurity Incident Involving Consumer Information

#310
post #14

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

I recently did this and highly recommend IdentityTheft.gov for assistance. It has tons of great resources/guidance for dealing with identity theft and other credit issues. https://www.identitytheft.gov/

Direct link to phone numbers for security freeze: https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq...
Post reply on HN