Fear not. You can check to see if you were affected by visiting their site and giving them more personal data: https://www.equifaxsecurity2017.com /s Maybe it doesn't matter much, since they've likely already got it. But, it feels a bit too soon. An interesting side-note: That domain was registered about two weeks ago on 8/22/2017. Whois reveals not a single pointer to Equifax (e.g. equifax.com email address, etc.).…
This comment should be nearer the top.
Also, equifaxsecurity2017.com appears to be a stock Wordpress site. Equifax is a bunch of fucking amateurs. Their security culture is broken.
I did this about 8 years ago, and have only needed to temporally unfreeze it 3 times. Besides the big 3, I also froze reporting from Innovis. The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.
Can you call and it get it unfrozen immediately if it needs to be run?
To unfreeze it entirely it looks like it can take no longer than 3 days. Unfreezing it for specific parties it sounds like is less money and perhaps takes less time but that will depend on the company.
> Right, and this is the point where we, as computer system / information security / software (whatever, but) professionals switch to using the word "authentication", and stop being obtuse about the ambiguity in the multiple definitions of the word "identity". Except it's nonsensical to switch to "authentication" when the discussion is about how the term "identity theft" is misleading. It's not "authentication theft"…
The point is that it is NOT "identity theft", even if that's what people call it. It is more aptly "authentication theft/fraud". The original point of this comment thread was that the credit reporting agencies want to keep it confusing so that it's not clear who exactly was the victim of the crime, so it's not obvious that the system sucks.
Yes, I agree, and I might have slightly misread what tripzilch wrote to mean that we should avoid the term here in this discussion, which I objected to. Towards the general public, it totally should be framed as an authentication failure, yes, I agree.
We don't know if this has anything to do with any acquisitions - this is a conjecture, at best. At any rate - I don't care. I never gave Equifax permission to collect my personal data. I certainly never gave them permission to store it in a way that it can easily be hacked. If you buy a 3rd party company, "unfuck" and harden their software BEFORE you let the data flow in. Allowing data to slip out is negligent. If yo…
The best way to punish them is for us all to organize and create a Proposition that bans them from being a credit bureau, etc. If this passes in California, it will destroy them as a company.
The problem here is that they've expanded their core business to be so pervasive, they're no longer reporting on just your credit history-- they've also moved into the employment history, salary history, etc. space. So you kill their financial tentacle, they'll still be collecting intelligence for other purposes.
> The thief would have to physically resemble the victim's photo Why? Show up to a government station with your birth certificate, SSN, some telephone and utility bills, and they'll take the thiefs picture and put it on an identity card with your name on it.
They don't use the SSN to check for prior IDs issued by other states and/or the Feds, and compare the applicant's photo/gender/age/height/eye color, etc to them first?
> This is not proof of identity. What is it then? I've seen it used as a quasi-password by car hire companies to access driving license history.
Do you see that thing above your post? "noja"? That's your identity. Your SSN on Hacker News. What proves that it is you to Hacker News is what you type into the password field when you log in.
My username isn't a semi-secret number that I have to guard.
Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity . Anywhere it is referenced it is repeated that it should not be used as proof of identity and not given to anyone as such. SSNs should be treated the same way, but that would require a culture change. Perhaps having 150m of them 'leaked' will bring about that change. Such a change could als…
Exactly. In the UK we have a National Insurance number, but it's stated over and over again that: This is not proof of identity. Here in the US, our Social Security Act said exactly the same thing. Guess what. It got used as a proof of identity.
Social Security cards used to say they weren't to be used as identification. They took that off because everyone ignored it and did what they wanted to anyway.
I did this about 8 years ago, and have only needed to temporally unfreeze it 3 times. Besides the big 3, I also froze reporting from Innovis. The only unforeseen hangup from frozen credit reporting I've run into is with car rentals. With a few exceptions, most car rental companies (at least in the US) run your credit. Everything else was pretty predictable.
> Besides the big 3, I also froze reporting from Innovis. Why Innovis? Who typically uses their reports?
Same people that pull from the other 3. It's not as commonly used, though its usage is trending upwards from what I understand.