Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

411–420 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#411
post #82

Earlier quoted context omitted.

Discovering a breach is only a fraction of what has to happen before customers/public should be notified of said breach. It's not very helpful to anyone if you put out a press release that just says "we discovered a breach but have no idea who, if anyone, was affected, we have no idea what was stolen, and we have no idea who did it." There have to be investigations that happen prior to any of that being known/release…

That seems reasonable, up to a point, but it also looks potentially self-serving and open to abuse (especially given the news about stock sales by insiders.) If a company in a position with this level of risk cannot staunch the leak within hours, it should be required to curtail its activities to the extent necessary to stop further leakage, until it has the proximate cause of the problem under control. Nor should th…

Building off your analogy, you don't order mandatory evacuations every time you see a tropical depression form out in the Atlantic. It's only when the tropical depression actually turns into a hurricane and is on a collision course that you warn the public.

Data breaches are the same. If you put out a press release every time your infosec team discovered an attack, you'd be putting out releases every single day, multiple times a day, even though most of those breaches would turn out to be inconsequential after investigation. The public would become totally desensitized to them. That's why the investigation has to be done to determine if there actually is something to notify the public about.

Now, there's surely a point in the investigation where you "know" that the public needs to be notified, but you aren't completely done with the investigation yet. It would probably be in the public interest to notify then rather than waiting, but I think companies are scared to do this because many companies in the past have been lambasted by the public for doing just that. Apparently people don't like it when you release a statement saying "we had a major breach and some customers are affected but we don't know who yet", so it seems that companies are opting to get all the facts before saying anything.

Re: Cybersecurity Incident Involving Consumer Information

#412
post #220
post #174

Earlier quoted context omitted.

Paper checks are going away. Some of the online banks don't even support them. ACH allows only 60 days to claw back the money(disputes) and with same day clearing requirement we can get rid of 2 day holds.

What are they being replaced with? Yeah, as a young renter I went years without using a check. When buying a home last year I had various inspectors during the process. After buying, I've had electricians, plumbers, contractors, locksmiths, and other consultants. I think one gave me a bill and accepted credit card. The rest preferred checks (to be fair, I didn't seek other forms). I've tried all sorts of p2p methods…

> I've had electricians, plumbers, contractors, locksmiths, and other consultants. I think one gave me a bill and accepted credit card. The rest preferred checks

Try cash? I use cash for almost all transactions like that and have never been turned down :-)

Re: Cybersecurity Incident Involving Consumer Information

#413
post #285

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Sounds like such a freeze should be the default state.

That doesn't sound very profitable.

Re: Cybersecurity Incident Involving Consumer Information

#414
Question: Is there any way to get a notification whenever a credit account of any sort has been opened in my name, WITHOUT freezing my credit or otherwise crippling/slowing/altering any process that exists? I just want a letter or email notification, not any other changes to anything. Ideally a free way, but paid if a free way doesn't exist...

Re: Cybersecurity Incident Involving Consumer Information

#415
post #102
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

Why must the consumer enroll in this? Why is it not automatic? They already pull all the strings with regard to keeping the consumer from taking out and keeping track of legitimate loans. Why must we go out of our way to prevent them from certifying and tracking illegitimate ones?

Most likely because Equifax is not providing the service and the actual provider will need to engage with each customer directly, despite the service being free.

Re: Cybersecurity Incident Involving Consumer Information

#416

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

This is actually a major inconvenience. You won't be able to apply for credit cards or get a loan to buy a car if you have a credit freeze. You have to unfreeze and re-freeze each time you apply for a credit card, and this costs about $30.

How often do you apply for credit? In the last 5 years I’ve done it zero times...

Re: Cybersecurity Incident Involving Consumer Information

#417
post #34

Oddly, on their website equifax.com , they offer a solution to see if your identity is stolen by using a website created today called equifaxsecurity2017.com , which then offers the solution to 'enroll' which sends you to a website created a week ago called trustedidpremier.com . At which point you are to enter your identity information. Um.

I've now been enrolled in one or more "identity monitoring" services going back at least five years offered in recompense for various breaches.... at some point it becomes ridiculous.

Same. Starting with the PlayStation hack a few years ago. If it makes you feel any better, I get notified by that service every time I do anything that accesses my credit at all, usually within minutes, so, I guess it works as designed.

Re: Cybersecurity Incident Involving Consumer Information

#418
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

Agreed. Thought experiment: suppose instead that Fraudster convinced Alice that he represented BigBank, and so Alice was duped and gave her money to Fraudster thinking she was depositing into BigBank. The only thing she could expect from BigBank was politeness while explaining to her that she was duped. If it's a very friendly bank, she may tie up a manager for a couple hours, but that's it. If she keeps coming back,…

> Now, what if she started falsely telling others that BigBank took her money, and that significantly affected BigBank's reputation? Are we talking jail time, or just civil penalties?

Probably not jail time, and perhaps not civil penalties. Even civil defamation in US law generally requires knowing falsehood or reckless disregard for the truth, not just mere falsehood, and criminal defamation, where it exists, tends to have high . Unless the bank had provided concrete evidence so solid that it was unreasonable for her not to believe their denial of responsibility, there likely be no legal wrongdoing.

Re: Cybersecurity Incident Involving Consumer Information

#419

Earlier quoted context omitted.

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> I want to see Equifax's CEO, CTO, CSO and anyone who ever saw a report saying "we need to invest more in security" and ignored it, to pay. Preferably with their jobs. No. With jail . And go bankrupt.

Now there are news that they sold their shares last week.

Re: Cybersecurity Incident Involving Consumer Information

#420

Earlier quoted context omitted.

> customer is on the hook for 7 years 7 years? Are you sure it's not something like 7 days?

It takes 7 years for a bankruptcy to clear your credit record in the USA.

That may be so, but the GP was talking about the time it takes checks to clear. IIRC, uncashed checks aren't even valid after 180 days, let alone 7 years.
Post reply on HN