How do you know if this affects you?
Cybersecurity Incident Involving Consumer Information
521–530 of 551 posts
Re: Cybersecurity Incident Involving Consumer Information
#522Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…
1.(added to qualify that adjective "honourable" which I apply to individuals not companies, and individuals who risk sacrifice without burdening others. My career is in advertising and I am truly impressed when publishers are able to maintain standards that are able to raise their costs of sales. (a large publisher may not lose a account, but the sale often consumes expensive energy, even only to explain why policies exist. I work far from such high sensitivity issues, as does the company I started around the time of this recollection.)
2. last I spoke to Mike, he was telling me how he simply was never issued his shares in "ElReg" and he was long enough into The Inquirer to think that Limitations applied. But Limitations 80 runs from the time of discovery of tort, not the event of tort. Before the chance arose to catch up, and establish facts, Mike had passed away. RIP a great man and two great journalistic servants to the IT community. I did not establish the facts that were alleged, therefore my statement is hearsay, but protected by the statutory defence of genuine belief, and I had always faith in my source.
Edit: italics removed from footnote, earn out replaced phypo earnings, and great man replaced good man. Mike was exceptional and altruistic to a fault.
Re: Cybersecurity Incident Involving Consumer Information
#523Credit Karma sent me an email this morning with the subject line "Your New Score" and I almost spit coffee all over my workstation. In fact my score only went down a point on Trans-Union, but it still was pretty scary to see in my inbox.
[0]: https://techcrunch.com/2017/09/07/equifax-data-breach-help-s...
Re: Cybersecurity Incident Involving Consumer Information
#524Earlier quoted context omitted.
I can't agree with this more. I was the victim of identity theft many years ago. I my case the data leaked from an employee at my company's payroll dept! There was nothing I could have done to prevent it. Anyway I did this many years ago and have not worried about it since. There is some small hassle because people run credit checks for weird reasons that have nothing to do with trying to get a loan or line of credit…
I'd phrase this more as, "I was impersonated by someone, and a third-party compounded the problem by lying about it to others. Now, to avoid that problem, I pay protection money to that third-party and waste my time jumping through their hoops." I do the same thing, BTW, because the alternative is worse. But it is a protection racket offered by the very people causing the problem.
Re: Cybersecurity Incident Involving Consumer Information
#525Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…
What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…
https://www.law.cornell.edu/uscode/text/15/1681h
In this case, maybe you could have a shot by arguing that since the bureaus know that like half the population's information was stolen, they are acting with reckless disregard for whether their statements are true if they don't now do additional investigation to confirm the identity of the subject of their statements in order to mitigate the effects of the breach.
Re: Cybersecurity Incident Involving Consumer Information
#526When they have no clue on what they are conveying about them to the people, these kind of clueless incidents do happen.
Re: Cybersecurity Incident Involving Consumer Information
#527My issue was swiftly resolved, but I felt the cold chill as replies came revised to note that overnight instructions for a separate matter were being notified to reflect the possible conflicts of interest the association rules require disclosed.
Barristers chambers can be used by opponent litigants, but with leave from the Master of Court, if not the Justice or Judge. I am thankful for my memory fading, and I actively discourage mistaking me for a authority. But I am not unwelcoming to inquiry from any request for anecdotal vignettes of IP and Companies Court cases, should be there need and understanding of my limitations. Laddie, LJ, was the solitary Lord Justice to ever resign the Queen's Bench. He was protesting the woeful incapacity of the Higher Courts to try specialised and particularly IP cases.
It was Laddie who handed down the scintillating condemnation of Manchester United soccer club for suing fans who knitted scarves in club colors.
Closer to home for many, Laddie is the one loss lamented by Patry, who wrote both testaments and the dead sea scrolls on US copyright and became a instrumental counsel to the growing young Google. Be unaware of this two names at your peril, in a litigious world of degenerate law for inventors and artists, and all who de novo create.
Edit, "bible" was a redundant word; separated paragraphs for clarity.
Re: Cybersecurity Incident Involving Consumer Information
#528Earlier quoted context omitted.
Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity". > For example, it is claimed that being able to say the DoB of Alice is an attribute that identifies Alice's body. And then we say that the stating the DoB authe…
> Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity". Except it's nonsensical to switch to "authentication" when the discussion is about how the term "identity theft" is misleading. It's not "authentication theft"…
The original point of this comment thread was that the credit reporting agencies want to keep it confusing so that it's not clear who exactly was the victim of the crime, so it's not obvious that the system sucks.
Re: Cybersecurity Incident Involving Consumer Information
#529Earlier quoted context omitted.
> I see this as you being too strict with your definition of "identity". > We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly…
> while it is claimed at the same time that they can be replicated by a "thief", which necessarily implies that they don't identify Alice, and hence are not an identity, therefore tautological impossibility. Attributes can be replicated -> attributes don't identify Alice Why do you consider this implication necessary? It sounds nonsensical. Counterexample: to verify an identity, the verifier must possess a replicatio…
Re: Cybersecurity Incident Involving Consumer Information
#530Earlier quoted context omitted.
You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html
I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…
To what end? As has been pointed out they have all that info anyway so it's not like you're making the situation worse.
But more importantly, if your credit is frozen who cares? What are they going to do with your SSN? Get a loan? Get a CC? Buy a house?
That's the point of a freeze, it makes your PII less valuable.
The actual concern is about the PIN. Because surely they could go through the trouble of PIN recovery to unfreeze your credit and then make use of it. But considering the numbers game, its not worth their trouble vs all the unfrozen accounts.