Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

331–340 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#333

Earlier quoted context omitted.

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus

Strange that this is being downvoted. The video is very relevant.

I get that many Americans are suspicious about our government, but the fact is that much of our credit / jobworthiness in the US is tied up in the Social Security card. I would rather it be something more useful, such as the Estonian National ID card -- which has smart features like digital contract signing.

Re: Cybersecurity Incident Involving Consumer Information

#334
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

"Now back when I worked in banking, if someone went to Barclays, pretended to be me, borrowed £10,000 and legged it, that was "impersonation", and it was the bank's money that had been stolen, not my identity. How did things change?" https://www.lightbluetouchpaper.org/2017/08/26/is-the-city-f...

Brilliant Mitchell and Webb from the comments there:

https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: Cybersecurity Incident Involving Consumer Information

#335

Earlier quoted context omitted.

> I see this as you being too strict with your definition of "identity". > We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly…

So the only way around this is to disregard information about a person other than information that 100% without a doubt identifies that person making a purchase is who they say they are? I am just genuinely curious.

Around what? The fact that the term "identity theft" is nonsensical? There is no way around that, it just is.

As for fraud: There probably is no easy way around it. But that doesn't mean it's not fraud.

Re: Cybersecurity Incident Involving Consumer Information

#336

"Three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers." https://www.bloomberg.com/news/articles/2017-09-07/three-equ... Edit: Also discussed here https://news.ycombinator.com/item?id=15196309

So, that should definitely get them busted for insider trading, no?

under this justice department?

Re: Cybersecurity Incident Involving Consumer Information

#337
post #155

Earlier quoted context omitted.

Wow. Equifax's Credit Freeze line is just dead. Must be getting slammed right now.

Their signup process for the credit freeze involves entering your SSN which is not obscured at all. It's increasingly obvious how this could have happened -_-

Care to elaborate?

Re: Cybersecurity Incident Involving Consumer Information

#338

Earlier quoted context omitted.

Your comparison is bullshit. I have control over how I secure my car from being stolen. It's complete nonsense to equate that to me being responsible for a bank's failure to protect themselves against fraud where I have no power whatsoever to influence how the bank secures itself against fraudulent loan applications.

Your statement is nonsense. Regardless of your efforts, the best you can ever hope for is to minimize the chance of your car being stolen. You can never prevent it completely. If your car is stolen in spite of your best efforts, are you at fault? Do you still have to deal with the consequences as a victim of that theft?

Which thus makes it equivalent to a scenario where you have no power to influence things whatsoever?

Re: Cybersecurity Incident Involving Consumer Information

#339
post #316

Earlier quoted context omitted.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

>carrying official ID It's probably not hard to forge a social security card and birth certificate if you have the relevant information. From there, a state ID (or maybe even passport) should be possible to get. I don't believe there is any biometric security on either. A determined identity thief might go that far.

The thief would have to physically resemble the victim's photo, height, age, gender, etc, which is some added defense in depth. For instance it would be hard for most males to pass themselves off as a typical female.

Re: Cybersecurity Incident Involving Consumer Information

#340

Earlier quoted context omitted.

For £100 you get a shiny credit rating for no risk. That'll get you a mortgage for £100,000s. In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. I appreciate that it probably benefited a certain type of person, but the new system probably has the same prejudices built in. Now it's all about the ephemeral and easily game-able credit score. Until a few years ago you would get negati…

> In the 60s/70s it was about knowing your bank manager, so he knew you'd be able to pay. You do recognize how terribly inefficient that is, right? In this day and age its all about scale. Expecting a bank manger to have financial profile of all the clients using his firm is impractical. For all it's faults, the credit reporting agencies are providing a service. It's not perfect and I think it's best they could do wi…

In reality the new credit agency model's been tested once, and it failed.
Post reply on HN