Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

441–450 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#441
post #69

Earlier quoted context omitted.

Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…

The problem is that you need a replacement, something that can actually be used as a solid proof of identity. The countries that don't have comparable identity theft problems have done so mostly by using an ubiquitous government issued ID that's hard to forge and hard to obtain by someone claiming to be you. In USA there seems to be a strong opposition and a legal barrier for the government to make such an ID. Not mu…

Can you expand on the systems that are "hard to obtain by someone claiming to be you" and biometrics? In my readings, I've found that biometrics is not unique across a large population, it changes over one's life span (which means you wouldn't know when it has changed enough to update the system that stores it), changes with one's profession (like physical labor) and health, and that the error rates across a huge population even for iris scans are quite high.

For reference, India has a unique ID called Aadhaar that collects ten fingerprints and two iris scans to deduplicate across 1.3 billion people. It uses flawed technology (relying on a fingerprint for authentication or in very rare cases, an iris scan), insecure devices, and generally has a high failure rate due to poor infrastructure. Combined with poor technology, the privacy and security policies and measures are inadequate too. There have been plenty of personal information leaked in the last few years because of the government's obstinate stand that this ID be linked to everything - phone numbers, tax ID, bank accounts, and many more.

I don't think there is any solution, including biometrics, that will work to uniquely and unambiguously identify individuals across large populations. I also see more dangers for the populace with such schemes because submitted biometrics, once compromised, cannot be revoked or reissued (this is how the Aadhaar system works - it stores the biometrics as-is).

Re: Cybersecurity Incident Involving Consumer Information

#442
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

If it was on the BigBank to always prove that their identity was indeed stolen, it would quickly become unmanageable. People would commit fraud in the opposite direction, by getting a huge loan from some a bank and claiming that their identity is stolen. I'm sure it would be easier than stealing someones identity to do it, and it would obviously involve some necessary actions to avoid being caught but this would driv…

In that case banks would just have to verify who they were giving money to before they start handing out loans. That doesn't sound particularly unmanagable to me.

Re: Cybersecurity Incident Involving Consumer Information

#443

Earlier quoted context omitted.

> Which makes your statement (that you have sufficient control to prevent the possibility of theft of your property) completely invalid. Luckily, I didn't say that.

> I have control over how I secure my car from being stolen. Really? Those were your exact words, in the context of claiming that your ability to secure your car made the comparison to identity theft invalid.

Do you really not understand the difference between having control over something and being able to guarantee it?

Re: Cybersecurity Incident Involving Consumer Information

#444
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

If it was on the BigBank to always prove that their identity was indeed stolen, it would quickly become unmanageable. People would commit fraud in the opposite direction, by getting a huge loan from some a bank and claiming that their identity is stolen. I'm sure it would be easier than stealing someones identity to do it, and it would obviously involve some necessary actions to avoid being caught but this would driv…

This would obviously drive the BigBank to collect some better evidence that the person applying for the loan is who they say they are, which is exactly the incentives we want here.

Re: Cybersecurity Incident Involving Consumer Information

#445

Earlier quoted context omitted.

I have heard of no cases where liability has been shifted in that way.

There is strong evidence for it here: http://www.cl.cam.ac.uk/~sjm217/papers/oakland14chipandskim.... And regardless of whether you claim the evidence is inconclusive, it is simply not acceptable to dismiss a known vulnerability in something important by saying "I don't know of any case where it has been exploited yet."

Exactly. All it does as far as I can see is flag the transaction as card holder present. The PIN is easy to steal as well evidenced by the number of fake reader heads and cameras found attached to ATMs as well.

Re: Cybersecurity Incident Involving Consumer Information

#446
post #150

Earlier quoted context omitted.

This is very clearly what's going on. Fraud is uncommon enough and the cost of fraud to the banks is smaller than the cost of reducing the velocity of money and loan-making, so the problem will never get fixed so long as it depends on the banks to initiate the fix.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

Verify that person's biometrics against the national database? I know that's what's happening in South Africa, a third-world country:

http://www.htxt.co.za/2015/09/16/this-is-how-banks-and-home-...

Re: Cybersecurity Incident Involving Consumer Information

#448
post #357
post #339

Earlier quoted context omitted.

The thief would have to physically resemble the victim's photo, height, age, gender, etc, which is some added defense in depth. For instance it would be hard for most males to pass themselves off as a typical female.

> The thief would have to physically resemble the victim's photo Why? Show up to a government station with your birth certificate, SSN, some telephone and utility bills, and they'll take the thiefs picture and put it on an identity card with your name on it.

That sounds incredibly bad for a first-world country. If that was the case, I'd argue that the entire country is in collapse. As you then have no control over foreigners impersonating locals and manipulating something as serious as elections, never-mind bank-fraud.

Edit: Point being, this needs to be fixed ASAP if you are to move your country into the future. Fix the regulatory/state hurdles that prevent it from happening, and get yourselves National Identification that's secure. Things will flow positively from there.

Re: Cybersecurity Incident Involving Consumer Information

#449
post #23

Earlier quoted context omitted.

I believe you CAN change your SSN https://faq.ssa.gov/link/portal/34011/34019/article/3789/can... . Especially if you have "cultural objections to certain numbers".

You can, but in very specific cases. The "cultural objections" bit requires documentation from a legitimate religious organization - you can't just say 123-45-6789 is the mark of Satan.

> legitimate religious organization

I've seen variations on this for exemption from educational requirements, ID requirements, medical requirements, and the like.

It's always struck me as odd that one _can't_ give as a reason "I have rationally concluded, based on the evidence I present here, that I will take X course of action."

But one _can_ say "I have been advised to take X course of action by a group of people who pinky-promise that they are authorised representatives of a sky fairy who suggested X to a hallucinating man several thousand years ago."

Re: Cybersecurity Incident Involving Consumer Information

#450
post #392
post #386

Earlier quoted context omitted.

What actually happens: 1. Alice does have debt, and does intend to acquire debt in the future, like most people. The presence of this fraudulent debt in her credit report makes credit more expensive and hard to get. 2. Before filing suit and going to court, BigBank makes persistent but usually polite attempts to collect. But when she says "that wasn't me" they don't believe her, because lots of deadbeats say that sor…

Step 3 is the insidious part. If Alice files a paper with the reporting agencies, they're required to remove the false report. But the collection agency will just as persistently file an equal but opposite paper to reinstate. The reporting agency is legally caught in the middle of he said, she said. And if asked for proof? The collection agency says BigBank told them Alice owed it, and sold them that debt. So now the…

If the credit reporting agencies wishes no responsibility then for all practical purposes they are a database table, nothing more. In that case they must offer their services on the same lines as AWS or Google Cloud. That is guarantee is only on infrastructure uptime and availability and not the quality of information. Note even in this case, a level of liability regarding security is on them.

If you wish to provide a service with a level of guarantee, responsibility and liability comes along with it.

Post reply on HN