Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

321–330 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#321
post #30

> Credit reporting agencies are one of the greatest/worst rackets in the modern financial system Can someone notify me when the class action has been initiated?

If you want to win big, initiate it. Members of the class are likely to get something stupid like free credit monitoring from Equifax.

I don't care about the payout. Honestly, the lawyers can keep it all, so long as they score a $50,000,000,000+ payout.

Oh, and the ability to force them to delete 100% of the information they have on my and never be allowed to store another bit.

Re: Cybersecurity Incident Involving Consumer Information

#322

From the article: "No Evidence of Unauthorized Access to Core Consumer or Commercial Credit Reporting Databases." Later on they say "The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver's license numbers." I am having a difficult time reconciling those two sentences.

Really makes you wonder what dataset this is, if it is apparently not consumer credit reports. And where did they get so much data on so many Americans?

Re: Cybersecurity Incident Involving Consumer Information

#323
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Clearly, both the bank and the individual are victims of the crime. Generally speaking, the impact to the customer is usually greater, as bank business model aren't dependent on every loan being repaid. Consumers stand to lose money directly and lose the opportunity to access capital. The credit agency or anyone else who has a breach is usually a negligent third party.

The individual isn't in any way a victim of the crime. A bank used some information presented to them to conclude that they were dealing with Alice when that information was objectively not sufficient to justify that conclusion. That has absolutely nothing to do with Alice. Alice is victimized in the next step by the bank when the bank claims that it somehow is Alice's responsibility that they took someone else for Alice.

Re: Cybersecurity Incident Involving Consumer Information

#324
post #216

Earlier quoted context omitted.

Same with chip and pin here in the UK

I have heard of no cases where liability has been shifted in that way.

There is strong evidence for it here: http://www.cl.cam.ac.uk/~sjm217/papers/oakland14chipandskim....

And regardless of whether you claim the evidence is inconclusive, it is simply not acceptable to dismiss a known vulnerability in something important by saying "I don't know of any case where it has been exploited yet."

Re: Cybersecurity Incident Involving Consumer Information

#325
This is very simple: the cost of this "incident" for Equifax is zero. As a smart business decision they are not investing (enough) in security and code quality because they don't need to.

Now if they knew that there is a $1000 fine per each stolen identity information, then the equation will shift and it will be a much better business decision to invest into protecting user data.

Re: Cybersecurity Incident Involving Consumer Information

#326

Earlier quoted context omitted.

> It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice. Credit Reporting agencies report the data passed to them by companies such as banks. In your scenario BigBank thinks it's given a loan to Alice, and when they don't get repaid, report that to the CRAs. Alice is a victim of the thief because her identity was appropriated to secure the funds. BigBank is a…

Your comparison is bullshit. I have control over how I secure my car from being stolen. It's complete nonsense to equate that to me being responsible for a bank's failure to protect themselves against fraud where I have no power whatsoever to influence how the bank secures itself against fraudulent loan applications.

Your statement is nonsense. Regardless of your efforts, the best you can ever hope for is to minimize the chance of your car being stolen. You can never prevent it completely. If your car is stolen in spite of your best efforts, are you at fault? Do you still have to deal with the consequences as a victim of that theft?

Re: Cybersecurity Incident Involving Consumer Information

#327
post #265

Earlier quoted context omitted.

From the r/personalfinance thread, the site kicks back 3 different JSON status messages: "message-deferred": "Thank You -- Your enrollment date for TrustedID Premier is: xxxxxx Please be sure to mark your calendar as you will not receive additional reminders. On or after your enrollment date, please return to faq.trustedidpremier.com and click the link to continue through the enrollment process." "message-success": "…

So... later date means they don't know yet? Or you have been impacted and you're only eligible to enroll later?

I really don't know. If we take it at face value, I think it means they're unsure and will hopefully know more later (whatever date it kicks back). At least, that's what I hope, because I gave in and punched in my information and I received the deferred message.

Re: Cybersecurity Incident Involving Consumer Information

#328

Earlier quoted context omitted.

> In no way was Alice's identity stolen - that's tautologically impossible. I see this as you being too strict with your definition of "identity". We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. "Stolen identity" in this sense means Alice's attributes (the ones which Big Bank uses to identify a person…

> I see this as you being too strict with your definition of "identity". > We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly…

So the only way around this is to disregard information about a person other than information that 100% without a doubt identifies that person making a purchase is who they say they are? I am just genuinely curious.

Re: Cybersecurity Incident Involving Consumer Information

#329
post #194

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

It's pretty much the flaw in not having a national ID scheme - everyone reaches for the next closest approximation, with no funding for security systems or refreshes to address flaws. Because this is an issue the government should address seriously.

US government has been addressing this but states (which tend to issue the identity documents used widely) pushed back. Here in Montana I will shortly have to use my passport to get through airport security for this reason.

Re: Cybersecurity Incident Involving Consumer Information

#330
post #30

> Credit reporting agencies are one of the greatest/worst rackets in the modern financial system Can someone notify me when the class action has been initiated?

If you want to win big, initiate it. Members of the class are likely to get something stupid like free credit monitoring from Equifax.

Sounds pretty likely. Sadly, I already have free credit monitoring from Equifax due to a previous identity theft incident. It's free for me, but paid for by another company that got hacked.
Post reply on HN