Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

351–360 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#351

Earlier quoted context omitted.

So the only way around this is to disregard information about a person other than information that 100% without a doubt identifies that person making a purchase is who they say they are? I am just genuinely curious.

Around what? The fact that the term "identity theft" is nonsensical? There is no way around that, it just is. As for fraud: There probably is no easy way around it. But that doesn't mean it's not fraud.

I was not saying either really. I was asking what sure fire way we have other than a number / name for identity.

Re: Cybersecurity Incident Involving Consumer Information

#352

Earlier quoted context omitted.

Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid. You can do everything right, and through no fault of your own have things go wrong.

> Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid. Luckily, I didn't say that.

> I have control over how I secure my car from being stolen.

Really? Those were your exact words, in the context of claiming that your ability to secure your car made the comparison to identity theft invalid.

Re: Cybersecurity Incident Involving Consumer Information

#353
post #38

> Equifax discovered the unauthorized access on July 29 Well over a month later and they're just now getting around to telling people about a security breach that could affect almost half of all Americans... How is this ok/legal?

The law gives them time to try to fix the problem before telling every hacker in the world about it.

In this context, there are two sorts of black-hat hackers: those who already know of the exploit, and those who do not. If it takes over a month to shut out the latter, then there is another problem.

Re: Cybersecurity Incident Involving Consumer Information

#354
post #306
post #292

Earlier quoted context omitted.

>and thus it's really hard to punish someone for cybersecurity mistakes No. If you take it upon yourself to hold this information, you are accepting the responsibility for its disclosure. If you are not willing to accept penalty for this happening despite your best efforts, you should not be doing it.

So, what should we do? Should we just fire/jail everyone who has ever worked for a company that was breached? You realize that would be literally everyone, in pretty much every company ever, right? There's a saying in the cybersec world: "there are two types of companies: those who know they've been hacked, and those who don't realize it yet". Cybersecurity is a field where there's already not enough good talent. And…

Oh come on. Anyone here who is a developer has at least some experience with raising a security concern to business or management and having it shot down as not important enough to worry about. We all know companies still aren't taking cybersecurity seriously enough, and it's because the consequences for a breach aren't severe enough.

Re: Cybersecurity Incident Involving Consumer Information

#355
post #283
post #40

Time for criminal penalties for the management team. A breach like this will affect thousands of people monetarily and suck time from them they could have used elsewhere. If you've ever dealt with something like this, you know the hours it takes to rectify the damage. The only way corporations will learn to appreciate data security is when management teams suffer criminal penalties.

We don't know how the security breach happened. Should Equifax be criminally liable for using software which contains a remote-exploitable buffer overflow vulnerability? Or for the actions of a corrupt employee who stole some data and sold it on the black market? It's possible that Equifax did something really negligent and if so maybe there should be a class-action lawsuit against the company. But it's also possible…

Isn't the traditional capitalistic argument that the people on top are the ones taking all the risk, which is why they should be making all of that money in the first place?

Note that I'm not making that argument, but trying to understand how this situation differs.

Re: Cybersecurity Incident Involving Consumer Information

#356

Earlier quoted context omitted.

Around what? The fact that the term "identity theft" is nonsensical? There is no way around that, it just is. As for fraud: There probably is no easy way around it. But that doesn't mean it's not fraud.

I was not saying either really. I was asking what sure fire way we have other than a number / name for identity.

Well, there is biometry, with the simplest form being a picture, if you want to somewhat reliably identify people.

Re: Cybersecurity Incident Involving Consumer Information

#357
post #339
post #316

Earlier quoted context omitted.

>carrying official ID It's probably not hard to forge a social security card and birth certificate if you have the relevant information. From there, a state ID (or maybe even passport) should be possible to get. I don't believe there is any biometric security on either. A determined identity thief might go that far.

The thief would have to physically resemble the victim's photo, height, age, gender, etc, which is some added defense in depth. For instance it would be hard for most males to pass themselves off as a typical female.

> The thief would have to physically resemble the victim's photo

Why? Show up to a government station with your birth certificate, SSN, some telephone and utility bills, and they'll take the thiefs picture and put it on an identity card with your name on it.

Re: Cybersecurity Incident Involving Consumer Information

#358
post #55

Earlier quoted context omitted.

And then I'll get six months of free credit monitoring from Equifax? Oh boy!!1! More seriously, this is a breach big enough that Equifax should honestly no longer exist as a company. So call it $100/incident, and I'm happy. Other agencies would still exist, and, although they're just as terrible, it might get them to kick their asses into high gear to fix their security.

The NYT story states that they are already offering this to affected consumers: https://www.equifaxsecurity2017.com/potential-impact/ .

Domain name was registered on August 22nd 2017...

Re: Cybersecurity Incident Involving Consumer Information

#359

Has equifax.ca also been affected? Does anyone have any intel on that? Now i'm worried

"Equifax also identified unauthorized access to limited personal information for certain UK and Canadian residents. Equifax will work with UK and Canadian regulators to determine appropriate next steps. The company has found no evidence that personal information of consumers in any other country has been impacted."

Fairly ambiguous and I trust that sentence about as far as I can throw it. I too am interested in the answer to this, both personally and as an employee of a company that uses their services.

Re: Cybersecurity Incident Involving Consumer Information

#360
post #84

>The company said that it discovered the intrusion on July 29 Why is this posted now?

Those consultants and experts need a month of pay to be called in to "brainstorm a response", of course :) And the response is great. "Please give us your SSN and last name, so that we can check to see if we exposed your info to being stolen ^.^ BRB TIME TO SELL ALL MY STOCK THANK U FOR UR PATRONAGE LOL ^.^"

Also if you sign up for our monitoring service you waive the right to a class action suit.
Post reply on HN