Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

381–390 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#381

Earlier quoted context omitted.

It takes 7 years for a bankruptcy to clear your credit record in the USA.

Ten, I think. Ten years. Or should I dispute that with the credit-reporting agencies?

Negative credit information falls off after 7 years from date of first delinquency.

Always dispute negative credit items; more likely than not, it won't be verified and is usually removed. Otherwise, wait 7 years and then dispute again.

Re: Cybersecurity Incident Involving Consumer Information

#382
post #375
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

>It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice. I think you're confused. It's BigBank that's falsely placing a debt burden on Alice. The credit reporting agencies are only reporting what they are told. Imagine if Alice doesn't care about her own credit worthiness. Let's say she has no debt, and no intention of acquiring debt. What happens if criminal…

It isn't BigBank warning her.. it is the collection agencies, but that's just semantics.

Re: Cybersecurity Incident Involving Consumer Information

#383

Earlier quoted context omitted.

Their signup process for the credit freeze involves entering your SSN which is not obscured at all. It's increasingly obvious how this could have happened -_-

Care to elaborate?

Shit-tier security practices

Re: Cybersecurity Incident Involving Consumer Information

#384
post #350
post #316

Earlier quoted context omitted.

>carrying official ID It's probably not hard to forge a social security card and birth certificate if you have the relevant information. From there, a state ID (or maybe even passport) should be possible to get. I don't believe there is any biometric security on either. A determined identity thief might go that far.

> A determined identity thief might go that far. This is the old "because a solution is not 100% effective, it's not good" chestnut. This solution would cut down on the theft by over 90%, I'd venture, probably more like 98%. There is huge difference between perpetrating a crime from the safety of a computer and physically walking into a bank to commit it.

$16 billion was stolen from 15.4 million U.S. consumers in 2016, compared with $15.3 billion and 13.1 million victims a year earlier. In the past six years identity thieves have stolen over $107 billion.

http://www.iii.org/fact-statistic/identity-theft-and-cybercr...

Re: Cybersecurity Incident Involving Consumer Information

#385
post #188
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

The credit agencies report what has been told to them by BigBank. Once the fraud is detected BigBank should update them that Alice does not in fact have a $10,000 loan with them and it would then be removed from Alice's report. If the loan has been determined to be fraudulent and it has not removed from her credit report, BigBank is victimizing her not the credit agencies.

> then be removed from Alice's report.

That's a long process (5+ years sometimes).

Re: Cybersecurity Incident Involving Consumer Information

#386
post #375
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

>It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice. I think you're confused. It's BigBank that's falsely placing a debt burden on Alice. The credit reporting agencies are only reporting what they are told. Imagine if Alice doesn't care about her own credit worthiness. Let's say she has no debt, and no intention of acquiring debt. What happens if criminal…

What actually happens:

1. Alice does have debt, and does intend to acquire debt in the future, like most people. The presence of this fraudulent debt in her credit report makes credit more expensive and hard to get.

2. Before filing suit and going to court, BigBank makes persistent but usually polite attempts to collect. But when she says "that wasn't me" they don't believe her, because lots of deadbeats say that sort of thing too.

3. Perhaps BigBank sells the debt to a collection agency, which is far more aggressive and (willfully?) ignorant of laws regulating how and when they can contact Alice. Perhaps they call Alice's employer, threaten to garnish her wages (even if they legally can't), or lie about Alice's ability to contest the debt.

4. If Alice is determined enough to keep fighting and go to court, she has still sunk significant time and money into fighting this. It's unlikely she'll be compensated fairly for that.

I agree the credit reporting agency is in some ways helping Alice, and would add that these agencies probably do reduce the rate of fraud overall. But they also have a responsibility to do a good job minimizing errors. We can't expect them to never make a mistake, but they should have some skin in the game when their inaccuracies hurt a credit applicant.

Re: Cybersecurity Incident Involving Consumer Information

#387
post #382
post #375

Earlier quoted context omitted.

>It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice. I think you're confused. It's BigBank that's falsely placing a debt burden on Alice. The credit reporting agencies are only reporting what they are told. Imagine if Alice doesn't care about her own credit worthiness. Let's say she has no debt, and no intention of acquiring debt. What happens if criminal…

It isn't BigBank warning her.. it is the collection agencies, but that's just semantics.

That's exactly the point. BigBank isn't going to warn anyone. It's just going to seek judgement, or sell the debt to shady collectors and write off the difference.

https://www.nytimes.com/interactive/2014/08/15/magazine/bad-...

Think about the credit reporting agencies as a rather sloppy "master list" of who owes who money. It seems what is needed are stiff penalties for banks and collection agencies who falsely claim they are owed money. Until then, you can't live in peace. Someone is going to claim you owe them money if you have any money yourself.

Re: Cybersecurity Incident Involving Consumer Information

#388

Earlier quoted context omitted.

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. The issue here is likely related to business units that were acquisitions, with the breached product in question having been developed pre-acquisition by a code farm staffed by interns in some developing nation. I spent a few years trying to unfuck some of those messes and moved…

We don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If yo…

The best way to punish them is for us all to organize and create a Proposition that bans them from being a credit bureau, etc. If this passes in California, it will destroy them as a company.

Re: Cybersecurity Incident Involving Consumer Information

#389

From the article: "No Evidence of Unauthorized Access to Core Consumer or Commercial Credit Reporting Databases." Later on they say "The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver's license numbers." I am having a difficult time reconciling those two sentences.

Exactly, they're being shady as fuck. They're trying to confuse people into thinking that their information wasn't stolen but it was, just those particular databases weren't affected.

Re: Cybersecurity Incident Involving Consumer Information

#390
Perhaps it is time for our companies and institutions to move away from social security numbers, credit cards, driver licenses and such stuff to having people authenticate using apps on their devices (or in person with biometrics).

iPhones now have the Secure Enclave, Androids have the Secure Element. You can store private keys there.

Authentication is done by apps signing challenges. This can be done in many ways, including oAuth, QR codes to authorize new devices etc.

Identity can be done by posting signed identity claims across websites, and adding/repudiating public keys in a personal scuttlebutt-type blockchain.

You can then easily sign into site X and prove your identity on sites Y and Z, without any sites necessarily tracking you between them.

Here is my semi-humble proposal for a decentralized, secure auth protocol that works with everything out there:

https://github.com/Qbix/auth

If you have experience writing tech specifications, please reply, I need someone to write the normative section of that protocol properly.

Post reply on HN