Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

521–530 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#522
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

I wish I could remember details, but a cofounder or single digit employee of a acquisition Equifax made, elected to forgo their earn out, because they were opposed to working in any capacity for Equifax. I think that they were somehow bullied into revealing their reasoning, to escape penalties in contract (which in any event were unlawful in the UK, I heard this from a employment attorney friend who has super reported cases, ie those which established new law). They were immediately snapped up by a startup in VA. Equifax managed to suppress their credit file completely. Preventing them from even renting a apartment for at least a year, and I believe it was a year before they had been even recognised by a US reporting agency and could open and operate a checking account. This was picked up by The Register, which still was then still Mike Magee's baby, so honourable 1., 2.. I can't find a link from my phone, but even if you never believe me the actual events happened, I bet you had a thought that you would not be surprised if it happened more often.

1.(added to qualify that adjective "honourable" which I apply to individuals not companies, and individuals who risk sacrifice without burdening others. My career is in advertising and I am truly impressed when publishers are able to maintain standards that are able to raise their costs of sales. (a large publisher may not lose a account, but the sale often consumes expensive energy, even only to explain why policies exist. I work far from such high sensitivity issues, as does the company I started around the time of this recollection.)

2. last I spoke to Mike, he was telling me how he simply was never issued his shares in "ElReg" and he was long enough into The Inquirer to think that Limitations applied. But Limitations 80 runs from the time of discovery of tort, not the event of tort. Before the chance arose to catch up, and establish facts, Mike had passed away. RIP a great man and two great journalistic servants to the IT community. I did not establish the facts that were alleged, therefore my statement is hearsay, but protected by the statutory defence of genuine belief, and I had always faith in my source.

Edit: italics removed from footnote, earn out replaced phypo earnings, and great man replaced good man. Mike was exceptional and altruistic to a fault.

Re: Cybersecurity Incident Involving Consumer Information

#523
The fact that they're using their press release, which lets people know how irresponsible they've been, to try and trick people into waiving their right to join a class action lawsuit against them is just the worst[0]. Sure, it may not hold up in court, but it's tricky and slimy and gross.

Credit Karma sent me an email this morning with the subject line "Your New Score" and I almost spit coffee all over my workstation. In fact my score only went down a point on Trans-Union, but it still was pretty scary to see in my inbox.

[0]: https://techcrunch.com/2017/09/07/equifax-data-breach-help-s...

Re: Cybersecurity Incident Involving Consumer Information

#524
post #210

Earlier quoted context omitted.

I can't agree with this more. I was the victim of identity theft many years ago. I my case the data leaked from an employee at my company's payroll dept! There was nothing I could have done to prevent it. Anyway I did this many years ago and have not worried about it since. There is some small hassle because people run credit checks for weird reasons that have nothing to do with trying to get a loan or line of credit…

I'd phrase this more as, "I was impersonated by someone, and a third-party compounded the problem by lying about it to others. Now, to avoid that problem, I pay protection money to that third-party and waste my time jumping through their hoops." I do the same thing, BTW, because the alternative is worse. But it is a protection racket offered by the very people causing the problem.

I think that pretty much is exactly how I felt about it at the time. One thing I haven't seen mentioned is the fact that this "remedy" was actually a requirement imposed (at least in California) on the credit agencies by the government, and it wasn't always that way. So for several years instead of this, I would have to actually go check (all three) credit agencies getting my "free" report (since I was an identity theft victim). Of course I still had to ask for it, they didn't just send it to me. So yes it was the least bad alternative. If a large enough people actually signed up for this it would actually destroy the credit agencies business model, because instead of working by default, they would be broken often enough that people would do other, more reliable solutions. I think they may already be happening in some cases. For instance when my son moved into his first apartment, I had to put my name on the lease. I told them my credit was locked and they said they don't use the credit agencies, they had some other check they did. So yeah, no love for credit reporting agencies from me..

Re: Cybersecurity Incident Involving Consumer Information

#525
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

What Alice is the victim of is slander , not fraud or identity theft. The bank lent some money to someone who claimed to be Alice (though the bank only relied on the fact that that person knew Alice's SSN as proof of that fact). Then when the bank didn't get paid back, they told a bunch of credit check bureaus that Alice was a credit risk. This was a lie about Alice, which has a material impact on Alice's reputation.…

I haven't dug too deeply into this, but a defamation claim under state law would probably be pre-empted by the Fair Credit Reporting Act. You mostly can't sue them unless you can prove they defamed you with malice or with willful intent.

https://www.law.cornell.edu/uscode/text/15/1681h

In this case, maybe you could have a shot by arguing that since the bureaus know that like half the population's information was stolen, they are acting with reckless disregard for whether their statements are true if they don't now do additional investigation to confirm the identity of the subject of their statements in order to mitigate the effects of the breach.

Re: Cybersecurity Incident Involving Consumer Information

#526
> Equifax is a global information solutions company that uses trusted unique data, innovative analytics, technology and industry expertise to power organizations and individuals around the world by transforming knowledge into insights that help make more informed business and personal decisions.

When they have no clue on what they are conveying about them to the people, these kind of clueless incidents do happen.

Re: Cybersecurity Incident Involving Consumer Information

#527
I have once gone so far as to write a preliminary claim for defamation and libel, and put the brief to clerks for barristers to indicate interest and availability.

My issue was swiftly resolved, but I felt the cold chill as replies came revised to note that overnight instructions for a separate matter were being notified to reflect the possible conflicts of interest the association rules require disclosed.

Barristers chambers can be used by opponent litigants, but with leave from the Master of Court, if not the Justice or Judge. I am thankful for my memory fading, and I actively discourage mistaking me for a authority. But I am not unwelcoming to inquiry from any request for anecdotal vignettes of IP and Companies Court cases, should be there need and understanding of my limitations. Laddie, LJ, was the solitary Lord Justice to ever resign the Queen's Bench. He was protesting the woeful incapacity of the Higher Courts to try specialised and particularly IP cases.

It was Laddie who handed down the scintillating condemnation of Manchester United soccer club for suing fans who knitted scarves in club colors.

Closer to home for many, Laddie is the one loss lamented by Patry, who wrote both testaments and the dead sea scrolls on US copyright and became a instrumental counsel to the growing young Google. Be unaware of this two names at your peril, in a litigious world of degenerate law for inventors and artists, and all who de novo create.

Edit, "bible" was a redundant word; separated paragraphs for clarity.

Re: Cybersecurity Incident Involving Consumer Information

#528

Earlier quoted context omitted.

Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity". > For example, it is claimed that being able to say the DoB of Alice is an attribute that identifies Alice's body. And then we say that the stating the DoB authe…

> Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity". Except it's nonsensical to switch to "authentication" when the discussion is about how the term "identity theft" is misleading. It's not "authentication theft"…

The point is that it is NOT "identity theft", even if that's what people call it. It is more aptly "authentication theft/fraud".

The original point of this comment thread was that the credit reporting agencies want to keep it confusing so that it's not clear who exactly was the victim of the crime, so it's not obvious that the system sucks.

Re: Cybersecurity Incident Involving Consumer Information

#529

Earlier quoted context omitted.

> I see this as you being too strict with your definition of "identity". > We, as people, have multiple identities. We have one with our government, another with our employer, another with our friends, another on pseudonymous websites, etc. Which is not relevant here, as this is not about different sets of attributes pointing to the same body, but about the exact same set of attributes being claimed to only possibly…

> while it is claimed at the same time that they can be replicated by a "thief", which necessarily implies that they don't identify Alice, and hence are not an identity, therefore tautological impossibility. Attributes can be replicated -> attributes don't identify Alice Why do you consider this implication necessary? It sounds nonsensical. Counterexample: to verify an identity, the verifier must possess a replicatio…

[deleted]

Re: Cybersecurity Incident Involving Consumer Information

#530

Earlier quoted context omitted.

You have to place the freeze on each of the three credit agencies individually. In most states it's $10 each, but it can vary state to state. https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo... https://www.transunion.com/credit-freeze/place-credit-freeze https://www.experian.com/freeze/center.html

I think you are missing something. Here's what's needed to initiate your TransUnion freeze: To set up a security freeze with TransUnion, please visit our online form. You should be prepared with the following types of information: 1. Your full name, including middle initial and suffix, such as Jr., Sr. II, III 2. Social Security Number 3. Date of birth 4. Current address 5. All addresses where you have lived during t…

> So, if I hack TU, all I need to do is get the data of the people who asked for a credit freeze.

To what end? As has been pointed out they have all that info anyway so it's not like you're making the situation worse.

But more importantly, if your credit is frozen who cares? What are they going to do with your SSN? Get a loan? Get a CC? Buy a house?

That's the point of a freeze, it makes your PII less valuable.

The actual concern is about the PIN. Because surely they could go through the trouble of PIN recovery to unfreeze your credit and then make use of it. But considering the numbers game, its not worth their trouble vs all the unfrozen accounts.

Post reply on HN