Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

511–520 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#511
From https://trustedidpremier.com/static/terms

"By consenting to submit Your Claims to arbitration, You will be forfeiting Your right to bring or participate in any class action (whether as a named plaintiff or a class member) or to share in any class action awards, including class claims where a class has not yet been certified, even if the facts and circumstances upon which the Claims are based already occurred or existed."

Sign for their TrustedID Premier and lose your rights.

Re: Cybersecurity Incident Involving Consumer Information

#512
post #421

The whole concept of these credit agencies infuriates me. I didn't sign up for it. You have a dossier on me that I have no part of. If you F it up, you'd better bend over backwards to make sure it doesn't affect me.

This simply isn't true. The only way these agencies get your SSN associated with your personal info is by your agreement with a bank or similar organization to do so. It always happens with your express approval, even if you are not savvy enough to pay attention to what you're approving.

"You could avoid being in Experian's database by becoming an off-grid hermit in Montana" isn't really a great response here.

Bank accounts, cars, housing, etc. are necessities, and consumers have no power to negotiate in a lot of cases. Good luck getting your bank or landlord to let you opt-out of credit reporting.

Re: Cybersecurity Incident Involving Consumer Information

#513

From the article: "No Evidence of Unauthorized Access to Core Consumer or Commercial Credit Reporting Databases." Later on they say "The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver's license numbers." I am having a difficult time reconciling those two sentences.

Really makes you wonder what dataset this is, if it is apparently not consumer credit reports. And where did they get so much data on so many Americans?

I'd imagine the vulnerability allowed the "people" table to be accessed, but not the full list of credit report items for those people.

As for how they got the info, if you have a bank account, a landlord, a student loan, etc., Equifax knows who you are. Virtually any organization that extends credit or collects unpaid debts is going to be reporting that to the three agencies.

Re: Cybersecurity Incident Involving Consumer Information

#514

People should be asking just how Equifax ended up with any of your private information. Do you authorize anyone to share this sensitive information with them?

> Do you authorize anyone to share this sensitive information with them?

Almost certainly. Any time you've taken a loan, opened a bank account, rented a car, etc. you've likely agreed to it in the fine print.

Whether you had any choice in the matter is a far more important question.

Re: Cybersecurity Incident Involving Consumer Information

#515

So in order to see if my sensitive data was stolen from an Equifax database, I have to enter my sensitive information into an Equifax database.

"Your data wasn't taken! Don't worry, it'll now be lost in the next hack, so you can have your free credit monitoring then."

Re: Cybersecurity Incident Involving Consumer Information

#516

So, can anyone tell me, why are there three credit agencies? Why not one, or thirty? Could I start a credit agency, just by judging that certain people are level 9000 reliable, and others are just level 100 reliable? I swear it's not slander, everyone I refer to is reliable, it's just that some of them have demonstrated exceptional reliability.

One would probably mean antitrust action or nationalization.

There are more than three - https://en.wikipedia.org/wiki/Innovis for example - but the big three are the ones with market power. Anyone can start one - but it's tough getting banks and landlords to use you, especially in the beginning when you've got no data. Massive barriers to entry.

Re: Cybersecurity Incident Involving Consumer Information

#517
post #170
post #40

Time for criminal penalties for the management team. A breach like this will affect thousands of people monetarily and suck time from them they could have used elsewhere. If you've ever dealt with something like this, you know the hours it takes to rectify the damage. The only way corporations will learn to appreciate data security is when management teams suffer criminal penalties.

I don't think it's fair to be throwing any individuals under the bus like that. There's obviously been several failures at multiple levels but the company as a whole will have to face the consequences, not just a few managers it decides to use as scapegoats.

How about a lot of managers, then?

Re: Cybersecurity Incident Involving Consumer Information

#518

This is where sovereign identity solutions on Blockchain show the way forward. For example check out Civic and Pillar. Non-disclosure: no commercial interest in them. We should own our own data and that must mean decentralised. All centralised data gets hacked - all.

> All centralised data gets hacked - all.

What, and no one ever lost their Bitcoins via a key breach?

Owning our own data has very, very significant security implications. The average human isn't technically prepared to be their own infosec department.

Re: Cybersecurity Incident Involving Consumer Information

#519
post #155

I strongly encourage anyone in the US to put a full credit security freeze on all three credit agencies. When a credit freeze is in place, you still have access to all of your existing loan accounts and whatnot (e.g. credit cards), but lenders cannot access your credit to open new accounts unless you want them to. It's not difficult nor expensive to do, and the freeze lasts until you decide to revoke it. Whenever you…

Wow. Equifax's Credit Freeze line is just dead. Must be getting slammed right now.

Also just tried to pull a credit report for Equifax via annualcreditreport.com and received a messages a condition exists at this time not allowing my report to be pulled and instead gave me mailing instructions.

Re: Cybersecurity Incident Involving Consumer Information

#520
post #150

Earlier quoted context omitted.

Work at a financial firm and have built a bunch of identity theft detection features. Curious what your fix would be. Identity theft and friendly fraud losses are in the tens of billions annually and identity verification services is a huge industry.

I've never talked about this with anyone who knows the industry so it may be stupid in some obvious way, but I would gladly accept the inconvenience of having to go to my bank in person, carrying official ID, when opening lines of credit, if it would make the whole process secure. Banks could serve the process of relatively slow but reliable authentication for specific financial transactions, and communicate those au…

Some thoughts in response to comments:

1. The bank should capture the ID you used the first time you entered and do comparisons. They should also capture your ID when you come in again. This will raise the difficulty of impersonating you and the risk the criminal takes.

2. One thing I didn't think to say, because my bank only exists in North Carolina: geography should matter. If you live in a particular city, opening an account from another state should be seen as suspicious, and merit greater checks. This is the kind of thing some people should be able to relax, but it's probably a good default for most of us.

3. Should I have to go to my bank for PayPal, Venmo, Betterment, eTrade, etc? Those cases don't all sound the same to me. But here's what I'd consider: how often is a person going to need to do this, and does the activity involve requesting credit? We've currently optimized almost exclusively for convenience at the expense of security. I'm proposing that we shift that balance a bit.

Post reply on HN