Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

471–480 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#471

Earlier quoted context omitted.

So, that should definitely get them busted for insider trading, no?

It depends... Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 scheduled trading plans. The…

I'm sure the SEC will get a copy of all emails, meeting schedules and chats of that time. If there was any phone call, meeting or email between one of these guys and someone with knowledge of the matter, it will be very hard for them to argue that they didn't know. Even if they weren't told details, they could've seen that the others were obviously dealing with something very serious.

Re: Cybersecurity Incident Involving Consumer Information

#472
Honest question from a European: how would this work if I moved to the US? Would I simply not get a loan because I don't have a credit score? Do I apply at private companies and give them all my loan history?

Here in my country the government (or some agency) keeps track of what loans you have, and when a new company wants to issue you a loan you access the API with information like "2 years, €50 each month" and then the program responds with 'approved' or 'not approved'.

Giving all of these private companies all this data seems counter to American values of independance etc...

Re: Cybersecurity Incident Involving Consumer Information

#474
post #439
post #194

Earlier quoted context omitted.

It's pretty much the flaw in not having a national ID scheme - everyone reaches for the next closest approximation, with no funding for security systems or refreshes to address flaws. Because this is an issue the government should address seriously.

Even with a national ID scheme, I don't know of any country who has implemented a way to validate that the holder of the ID document is the person who is the person who the ID document corresponds to without the person being present so that their biometric data can be validated.

You can use many ID cards online with the chip in the card. This means you need to have access to the physical card and the PIN. Much safer than just having a number and it will be hard to steal 50 million physical ID cards.

Many banks use video chats to open accounts where you have to present the card via video. This can be even safer as you need the physical card and someone who looks like the person on the ID card. Since calls are recorded, I can imagine fraudsters are hesitant to use this process.

Re: Cybersecurity Incident Involving Consumer Information

#475

Earlier quoted context omitted.

You're right it was never meant to be a unique identifier, we need a national identification card, link to a video about it. https://youtu.be/Erp8IAUouus

Americans don't like National ID cards because we remember the Third Reich and the USSR.

You don't need one central register with intimate data of citizens. You can keep registers local to avoid widespread data breaches. It's still possible to verify the authenticity (e.g. for police) by requesting from the local register (electronically) but no one has access to all data at once.

At the same time, the system can be designed to only store the data necessary. Don't think it's necessary to store more information than for SSID.

Re: Cybersecurity Incident Involving Consumer Information

#476
post #376

Earlier quoted context omitted.

Seems KYC as used in the real world doesn't do a very good job of verifying whether the "customer" is Alice or the fraudster... It'd be nice if _that_ requirement had enough teeth to reduce the ability of the financial institution to claim Alice is "the victim"...

Curious how would you verify a user? Right now standard solution is to use public records(LexisNexis), credit history(Experian), fraud detection networks(early warning). Along with a bunch reputation providers around IP(Maxmind,Socure), email(emailage), address. Also government based ID and utility bills etc. This isn't cheap and can costs $10+ to run all these checks. Even government can't verify people and its prob…

You ask for their ID card or passport. If you want credit history, you ask for their last year tax sheet.

Re: Cybersecurity Incident Involving Consumer Information

#477
post #36

Earlier quoted context omitted.

The SSN was never intended as a national ID. It was originally created alongside the Social Security Administration, to track what individuals put in and what they take out. People only received one upon becoming employed. Over time, the IRS realized that it could be used as a national ID, and adopted it for that purpose. They encouraged people to obtain one from a young age (even for their newborn children), and it…

Why do we need to number people anyway? People are very consistent with spelling their own names. This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. Think about passwords. A SSN is only nine digits, 0-9. JohnHarrySmith19900101NewYork is far more secure. And doesn't dehumanize the recipient.

In Germany, this is how identification works to some degree. You have an ID card number but this changes with every card. There is a permanent tax number but this isn't used for anything but tax purposes.

In the end, identification can be done by name, birth date and place of birth. You'll find these requirements on many official forms. This is fairly unique and ties to birth certificates which can be obtained with this information. Even if all databases were erased, this data could restore registers (as birth certificates have a paper copy).

Re: Cybersecurity Incident Involving Consumer Information

#478

Earlier quoted context omitted.

Why do we need to number people anyway? People are very consistent with spelling their own names. This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. Think about passwords. A SSN is only nine digits, 0-9. JohnHarrySmith19900101NewYork is far more secure. And doesn't dehumanize the recipient.

> People are very consistent with spelling their own names. Is this true of all people? > This combined with a birth date and/or a birth city should be enough to uniquely identify anyone. For common names and large cities, probably not. > JohnHarrySmith19900101NewYork is far more secure. No, it's not; SSNs aren't passwords, and shouldn't need to be “secure” in that sense, but names aren't secret and birth dates and l…

> For common names and large cities, probably not.

Would be interesting to see statistics for that. It wouldn't be New York in this case, but for example Brooklyn or Queens. Even for the most popular name combinations, the number of people with the same name born on one day in one administrative area will be extremely low. Esp if you require middle names to be included.

Re: Cybersecurity Incident Involving Consumer Information

#480

Earlier quoted context omitted.

You've sold me, now tell me how to do it

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

thanks for this info! saved me a lot of time hunting these links down myself
Post reply on HN